The enterprise MDM dashboard shows that 200 Android devices have not received OS updates in over 2 years. The device model is a popular mid-range Android phone from a manufacturer that stopped software support for the model in 2024.
An MDM administrator notices that a fleet of corporate Android devices are all showing a 'May 2024' security patch level even though it is now June 2026. What is the security risk and recommended enterprise response?
- A.A) Devices running a 2-year-old security patch level are exposed to all publicly disclosed CVEs in the Android Security Bulletins from June 2024 to June 2026, including critical vulnerabilities in the media framework, Bluetooth stack, kernel, and vendor components. Enterprise response: (1) identify the specific CVEs from 24 months of bulletins and assess exploitability; (2) implement compensating controls (MDM network segmentation, restricting risky features); (3) accelerate device replacement program - hardware that is end-of-support cannot be remediated by patching.
- B.B) 2-year-old patches represent no significant risk because most Android vulnerabilities require physical access to exploit.