Pre-release of Android 13. Vulnerability removed in Android 12

Google has released the first beta version of the open mobile platform Android 13. The official release of Android 13 is expected in the third quarter of 2022. A beta testing program has been offered to evaluate the new capabilities of the platform. Firmware builds are prepared for Pixel 6/6 Pro, Pixel 5/5a, and Pixel 4/4 XL/4a/4a (5G) devices.

Key innovations of Android 13:

  • A system interface for selecting photos and videos has been implemented, as well as an API for selectively granting apps access to chosen files. It supports working with both local files and data stored in cloud repositories. A feature of this interface is that it allows access to individual images and videos without granting the app full access to view all multimedia files in storage. A similar interface was previously implemented for documents.
    Pre-release of Android 13. Vulnerability removed in Android 12
  • A new type of permission for Wi-Fi has been added, giving applications designed to search for wireless networks and connect to access points access to a subset of the Wi-Fi management API, excluding calls related to location determination (previously, applications connecting to Wi-Fi also had access to location information).
  • An API has been added for placing buttons in the quick settings section at the top of the notification dropdown panel. With this API, an app can request to place its quick action button, allowing users to add the button without leaving the app and separately navigating to settings.
    Pre-release of Android 13. Vulnerability removed in Android 12
  • The ability to adapt the background of app icons to the color scheme of the theme or the color of the background image has been provided.
    Pre-release of Android 13. Vulnerability removed in Android 12
  • The ability to bind individual language settings to applications has been added, differing from the language settings selected in the system.
  • Word wrapping operation has been optimized (breaking words that do not fit the line using a hyphen). In the new version, the performance of wrapping has increased by 200% and now has virtually no impact on rendering speed.
  • Support for programmable graphics shaders (RuntimeShader objects) defined in the Android Graphics Shading Language (AGSL), a subset of the GLSL language adapted for use with the Android platform's rendering engine, has been added. Such shaders are already utilized within the Android platform to implement various visual effects, such as pulsating, blurring, and stretching while scrolling beyond the page edge. Similar effects can now be created in applications.
  • The core Java libraries of the platform and app development tools have been updated to OpenJDK 11. The update is also available through Google Play for devices running Android 12.
  • As part of the Mainline project, which allows updating individual system components without updating the entire platform, new updatable system modules have been prepared. The updates affect hardware-agnostic components that are loaded through Google Play separately from OTA firmware updates from manufacturers. Among the new modules that will be able to update through Google Play without a firmware update are Bluetooth and Ultra wideband. Modules with Photo picker and OpenJDK 11 are also distributed through Google Play.
  • Optimizations have been made for building app interfaces for larger screens used on tablets, foldable devices with multiple screens, and Chromebook laptops.
  • The testing and debugging of new platform features have been simplified. Changes can now be selectively enabled for applications in the developer options section or via the adb utility.
    Pre-release of Android 13. Vulnerability removed in Android 12

Additionally, a February patch set has been released to address security issues for Android, which fixed 37 vulnerabilities, of which 2 are classified as critical severity and the rest as high severity. Critical issues allow for remote attacks to execute code on the system. Problems marked as high severity enable code execution in the context of a privileged process through manipulation of local applications.

The first critical vulnerability (CVE-2021-39675) is caused by a buffer overflow in the GKI_getbuf function (Generic Kernel Image) and allows remote privileged access to the system without any action from the user. Details about the vulnerability are not yet disclosed, but it is known that the issue only affects the Android 12 branch. The second critical vulnerability (CVE-2021-30317) is present in closed components for Qualcomm chips.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster