proomt

Search

Search posts, papers, and topics

All posts

InfoQSergio De Simone2 min readintermediate

Google's Android Security State Libraries Enable Component-Level Security Verification

Summary

Google's AndroidX Security State libraries enable Android apps to verify security patch status at a granular, component level, moving beyond a single device-wide patch number. This allows apps to identify missing patches and enforce security requirements before sensitive operations.

  • Verify security patch status per component (OS, modules, kernel) instead of a single device-wide Security Patch Level (SPL).
  • Distinguishes between Device SPL (installed), Published SPL (latest), and Available SPL (downloadable).
  • Apps can programmatically check for specific CVEs or if the device has installed all available security patches.
  • Enables security-critical apps (e.g., banking, MDM) to require component-specific updates before sensitive actions.

Android developers building security-sensitive applications or MDM solutions can now implement more precise security checks and enforce component-specific update requirements.

6/10

Related reading

  1. Android 17 Without the Last-Minute Scramble

    CodeName One prepared for Android 17 (API 37) by addressing platform changes proactively, including fixing version number parsing and implementing the new system-rendered location button. They also added robust PEM key parsing and explicit task removal to simplify common security operations for app developers.

    CodeName Onecodenameone.com8 min
  2. Tapjacking Protection: Rejecting Android Touches Behind an Overlay

    Codename One adds tapjacking protection to its Android runtime. It detects fully or partially obscured MotionEvents, offers four policies (OFF, REPORT, BLOCK, STRICT), can block the entire gesture, and on Android 12+ can request the system hide overlay windows. The API is exposed via `DeviceIntegrity.setTapjackingProtection` and a listener for state changes. iOS has no overlay threat, so the feat…

    CodeName Onecodenameone.com3 min
  3. App Hardening: One Obfuscation Pipeline Across Every Port

    Codename One adds a cloud‑side hardening step that runs on the merged JAR before it is split into Android, iOS, JavaScript, and desktop binaries. It can rename symbols, encrypt string literals, and insert opaque‑predicate control‑flow guards at configurable levels (off → standard → aggressive → paranoid). The transforms are selective per platform to avoid breaking optimizers, and a mapping is kep…

    CodeName Onecodenameone.com6 min
  4. We Stopped Waiting for Platform Changes to Find Us

    Codename One added a daily automated scan of Apple and Google deprecation notices, linking each notice to concrete builder artifacts before work is created. The system caught the Android 16 back‑gesture change and enabled a permission‑free ContactPicker, turning policy shifts into repeatable, evidence‑backed patches.

    CodeName Onecodenameone.com3 min