Helpnetsecurity Google Releases AndroidX Security State Libraries for Enhanced Device Security
Article Content
- •Google launched AndroidX Security State libraries for detailed device security checks.
- •Developers can now assess individual component security with DSPL, PSPL, and ASPL.
- •The libraries help prevent exploitation by ensuring critical updates are installed before sensitive actions.
On September 18, 2026, Google announced the stable release of the AndroidX Security State libraries, version 1.1.0 and 1.0.0, which allow developers to check the security patch status of individual device components. This new functionality enables a more granular approach to assessing device security, moving beyond the traditional Security Patch Level (SPL) system. Developers can now access three patch levels: Device Security Patch Level (DSPL), Published Security Patch Level (PSPL), and Available Security Patch Level (ASPL). This allows for better decision-making in security-sensitive applications, such as banking and healthcare, by verifying if critical updates are pending before executing sensitive workflows. The libraries also integrate with the Open Source Vulnerabilities (OSV) database for detailed vulnerability reports. The introduction of these libraries is part of Google's ongoing efforts to enhance security in the Android ecosystem.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Cisco and CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents A zero-click remote code execution vulnerability, named Plugin4Shell, affects major AI coding agents including Claude Code, Codex, Copilot, and Gemini. This vulnerability allows attackers to exploit a flaw in the SHA-pinning mechanism of trusted plugin marketplaces, enabling full access to sensitive data and systems…
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation Cisco has disclosed a critical vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via a flaw in an API endpoint. This vulnerability has a CVSS score of 10.0 and is actively being exploited in the wild, prompting Cisco to issue…