The changes that Google is bringing to the way it distributes its security code on Android, further enhance security on all Xiaomi phones
Η Google has officially changed its distribution policy for Android security updates. This significant change directly impacts the distribution of critical Android security updates to key partners, including Xiaomi.
The new distribution will givePriority to OEMs through private channels, under a new confidentiality agreement. This will ensure that all Xiaomi devices that “run” the HyperOS will become more secure, long before vulnerability information is released to the general public, making devices safer for end users.
This new Google distribution policy will make the entire security ecosystem stronger for all Xiaomi phones.
What is Evolutionary in Android Security?
Google is reportedly distancing itself from publicly disclosing vulnerabilities in Android. Google will first deliver security updates directly to well-known smartphone manufacturers like Xiaomi, rather than making them openly available for public distribution.
The New Three-Month "Embargo Period"
The best feature of this new policy is the required three-month confidentiality agreement with OEM manufacturersThis agreement requires the three-month "embargo period".
Inside this 90 day period, Smartphone manufacturers like Xiaomi will not be able to release the “source code” of the security updates they receive.
This change will not delay the security code updates that users receive, as OEMs will be completely free to release the already translated and compiled binaries releases of security code updates to public distributions.
This will allow for the rapid release of updates to the code on your Xiaomi Pad or Redmi phone for example, while keeping the dangerous code protected from the possibility of third parties exploiting the vulnerability it has.






