As Android moves away from C/C++ to a larger proportion of Java and Rust, its security vulnerabilities are measurably decreasing!
miniblog.
Related Posts
I'm intrigued to see that Google has quantified that new code is generally buggier and less secure than code that has existed in your codebase for longer:
Super impressed that the UK government does regular scanning for vulnerabilities for servers based in the UK: https://www.ncsc.gov.uk/information/ncsc-scanning-information
Preventative and good for the overall ecosystem.
Spectre vulnerabilities remain a problem in browsers, and the PoC even works on new Apple silicon!
