For me, personally, it's a race to see if Google can get this patched for my Pixel 5 before security updates stop in October.
For me, personally, it's a race to see if Google can get this patched for my Pixel 5 before security updates stop in October.
Looks like this is it [1] and it looks like LineageOS 17 is supported even back to Pixel 3a [2].
[1]: https://review.lineageos.org/c/LineageOS/android/+/366611
[2] https://forum.xda-developers.com/t/lineageos-17-for-pixel-3a...
I actually looked into it, my previous phone was released in June 2020.
The last security update for the phone came out in January 2022.
I'm not sure whether they're just updating things infrequently or whether that model is abandoned altogether, but neither would speak highly of the Android support landscape for non-flagship phones.
This ends up being kind of silly: if I want to have a mostly secure backup device (for 2FA and my bank/eID apps), then I probably need two comparatively recent devices, since a 5 year old budget phone would no longer quite do as a temporary daily driver, in case I'd lose my main phone.
I can say that their rugged designs served me well, but some of the newer phones apparently have this weird component for wireless earphones and I don't really want that, so my current and future purchases are from different manufacturers. Was actually pretty close to stock Android, though!
Pixel 5 should still qualifiy for it.
The security bulletin doesn't reference this CVE specifically but does mention a critical vulnerability that could lead to RCE.
https://support.google.com/product-documentation/answer/1141...
Good luck setting things up in such a way that you only get security patches and not a whole bunch of 'improvements' to go with them.