As the calendar changes to March, here we have the Google Pixel and Nexus March 2018 Android security updates. The latest factory images and OTA update zip files are now up for download. This March update resolves a number of security vulnerabilities in this release, with most of them marched as ‘Critical’. About 16 issues were resolved in the 2018-03-01 patch and 21 in the 2018-03-05 patch. Android partners have already been notified of the issues almost a month back before these issues are highlighted and published by Google.
Apart from the Android Security Bulletin, Google has also released a similar bulletin report the Google Pixel and Nexus devices. Among 40+ security issues, Google has also added 3 functional updates for the Pixel 2 and Pixel 2 XL phones. Most notably, it resolves the slow fingerprint unlock problem that several users have reported about on the Google Product Forums.
UPDATE: April 2018 Google Pixel and Nexus Android security update is now available. Download now!
Google Pixel / Nexus Security Bulletin – March 2018
You can find the latest Google Pixel and Nexus March 2018 factory image links below for the supported devices: Pixel 2 XL, Pixel 2, Pixel XL, Pixel, Pixel C, Nexus 6P, and Nexus 5X.
The OTA update should also be rolling out right now in stages to these supported devices. To check the security level of your Google Pixel or Nexus device, or if you want to check if this update is available for you, go to Settings > System > System update > Check for update.
Here is a list of all the functional updates included in this March 2018 update:
- [Performance] Improve screen wake performance with fingerprint unlock – Pixel 2, Pixel 2 XL
- [Audio] Improve audio performance when recording video – Pixel 2 XL
- [Reporting] Improve crash reporting – Pixel 2, Pixel 2 XL
As for the security updates, this is what Google has to say about the issues labeled as high or critical:
The most severe of these issues is a critical security vulnerability in Media framework that could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process. The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed.
We have had no reports of active customer exploitation or abuse of these newly reported issues.
Download Google Pixel / Nexus March 2018 Factory Images
Here are the download links for those who want to flash their phones manually without waiting for the over-the-air update to arrive:
Download March 2018 Security Update for Pixel 2 XL: Download Factory Image
Download March 2018 Security Update for Pixel 2: Download Factory Image
Download March 2018 Security Update for Pixel XL: Download Factory Image
Download March 2018 Security Update for Pixel: Download Factory Image
Download March 2018 Security Update for Nexus Pixel C: Download Factory Image
Download March 2018 Security Update for Nexus 6P: Download Factory Image
Download March 2018 Security Update for Nexus 5X: Download Factory Image
NOTE: If installing these factory images on your Google Pixel or Nexus devices, you also need the latest fastboot tool. You can get it from the Android SDK Platform-Tools package, which you can download here.
[Via Android, Pixel Security Bulletin]