Whether to update the firmware on a personal phone is a personal choice.
Some install CyanogenMod, while others feel they are not in control of the device without TWRP or jailbreak.
In the case of updating corporate mobile phones, the process should be relatively uniform; otherwise, even Ragnarök will seem like fun for the IT staff.
Read below about how this works in the 'corporate' world.

Brief Overview
iOS-based mobile devices receive regular updates similarly to Windows devices, but with the following differences:
- updates are less frequent;
- most devices receive updates, but not all.
Apple releases the iOS update simultaneously for most of its devices except those that have been discontinued. Apple supports its devices for quite a long time. For example, even the iPhone 6s, which came out in 2015, will receive the iOS 14 update. Of course, there are issues, such as the forced slow-down of older models, which, as stated, was not intended to force the purchase of a new phone, but to prolong the lifespan of the old battery... However, it's still better than the situation with Android.
Android is essentially a franchise. The original Android from Google is found only on Pixel devices and budget devices that participate in the Android One program. On other devices, only derivatives of Android can be found – EMUI, Flyme OS, MIUI, One UI, etc. This variety is a major problem for the security of mobile devices.
For instance, the 'community' finds another vulnerability in Android or the system components that underpin it. The vulnerability is then assigned a number in the CVE database, the finder receives a reward under one of Google’s bounty programs, and only after that does Google release a patch and include it in the next Android release.
Will your phone receive it if it is not a Pixel or does not participate in the Android One program?
If you bought a new device a year ago, then probably yes, but not immediately. The manufacturer of your device will still need to integrate Google’s patch into their Android build and test it on the supported device models. High-end models tend to be supported a bit longer. Everyone else has to accept this and avoid checking the CVE database in the mornings to preserve their appetite.
The situation with major Android updates is generally even worse. On average, a new major version reaches mobile devices with custom Android at least a quarter later, if not more. For instance, the Android 10 update from Google was released in September 2019, but devices from various manufacturers that were fortunate enough to qualify for the update received it only up until the summer of 2020.
Manufacturers can be understood. The release and testing of new firmware incurs significant costs. Since we have already purchased the devices, they can't extract additional money from us.
So, we are left with... being forced to buy new devices.

The vulnerability of Android builds from certain manufacturers has prompted Google to change the architecture of Android to deliver critical updates independently. This project is called Google Project Zero, and around a year ago, it was discussed on Habr. The feature is relatively new but has been integrated into all devices since 2019 that have Google services. Many know that these services are paid for by device manufacturers, who pay royalties to Google, but few realize that the matter goes beyond commerce. To get permission to use Google services on a specific device, the manufacturer must submit their firmware to Google for verification. Google does not accept firmware for verification that runs on outdated versions of Android. This allows Google to impose its Project Zero on the market, which we hope will make Android devices more secure.
Recommendations for corporate users
In the corporate world, not only publicly available applications from Google Play and the App Store are used but also custom-developed applications. Sometimes, the lifecycle of such applications ends upon signing the acceptance certificate and payment for the developer's services as per the contract.
In this case, installing a new major OS update often results in these job-is-done applications ceasing function. Business processes come to a halt, and developers are re-hired until the next issue arises. The same happens when corporate developers fail to adapt their applications to the new OS on time or a new version of the application is already available, but users have yet to install it. Systems of the class are intended to address such problems. .
UEM systems provide real-time management of smartphones and tablets by promptly installing and updating applications on mobile employees' devices. Furthermore, they can roll back the application version to a previous one if necessary. The ability to revert to an earlier version is an exclusive feature of UEM systems, which neither Google Play nor the App Store offer.
UEM systems can remotely block or defer firmware updates on mobile devices. The behavior depends on the platform and manufacturer of the devices. On iOS in supervised mode (read about the mode in our ) it is possible to postpone an update for up to 90 days. To do this, it's enough to set the appropriate security policy.
On Android devices from Samsung, it is possible to prohibit firmware updates for free or use the additional paid service E-FOTA One, which allows specifying which OS updates to install on the devices. This gives administrators the opportunity to check the behavior of corporate applications on new firmware of their devices in advance. Understanding the labor intensity of this process, we offer our clients a service based on Samsung E-FOTA One, which includes testing the functionality of targeted business applications on the client’s used device models.
Unfortunately, similar functionality is not available on Android devices from other manufacturers.
The only way to prohibit or defer updates is through scare tactics like:
"Dear users! Do not update your devices. This may lead to applications becoming non-functional. If you violate this rule, your requests for technical support will NOT BE CONSIDERED/HEARD!".
Another recommendation
Stay updated with the news and corporate blogs of operating system manufacturers, devices, and UEM platforms. Just this year, Google decided to support for one of the possible mobile strategies, namely fully managed devices with work profiles.
Behind this long name lies the following scenario:
Until Android 10, UEM systems fully controlled the device I can use work profile (container), which contains corporate applications and data.
Starting with Android 11, full management functionality is only possible OR device OR with a work profile (container).
Google explains the new features as a concern for user data privacy and its own wallet. If there is a container, then the user's data must remain out of sight and control of the employer.
In practice, this means that knowing the location of corporate devices or installing applications necessary for the user's work, which do not require placement in the container to ensure the protection of corporate data, is now impossible. Either you have to give up the container for this…
Google claims that such access to personal space deterred 38% of users from installing UEM. Now, UEM vendors have to make do with what they are given.

We have prepared in advance for these innovations and this year will offer a new version , which will take into account Google's new requirements.
Little-known facts
In conclusion, here are a few little-known facts about mobile OS updates.
- Firmware on mobile devices can sometimes be rolled back. As shown by an analysis of search phrases, the phrase 'how to restore Android' is searched more often than 'Android update'. It seems one can't put the meat back into the sausage, but it is indeed sometimes possible. Technically, protection against rollback is based on an internal counter that does not increase with each firmware version. Within a single value of this counter, reverting becomes possible. This applies to Android. The situation is slightly different for iOS. From the manufacturer’s website (or countless mirrors), one can download the iOS image of a specific version for a specific model. To install it via cable using iTunes, Apple must sign the firmware. Usually, in the first few weeks after the release of a new iOS version, Apple signs previous firmware versions so that users whose devices start glitching after an update can revert to a more stable build.
- In the days when the jailbreak community had not yet dispersed to large companies, one could change the displayed iOS version in one of the system plist files. For example, one could make iOS 6.2 show as iOS 6.3 and back. The reasons for this will be explained in one of the following articles.
- There is a clear universal love among manufacturers for the smartphone flashing program Odin. No better tool for flashing has been created yet.
Feel free to write, and we can discuss... maybe we can help.
Source: habr.com
