Google Introduces AndroidX Security State Libraries for Component-Level Patch Verification
- Google has released the AndroidX Security State library version 1.1.0 and the Security State Provider library version 1.0.0, providing developers with a centralized mechanism to perform component-level security...
- The new libraries enable applications to query the security status of specific parts of the Android software stack rather than relying on a single date-based patch level.
- The Security State library introduces three specific patch levels to provide a comprehensive view of a device's security status.
Google has released the AndroidX Security State library version 1.1.0 and the Security State Provider library version 1.0.0, providing developers with a centralized mechanism to perform component-level security verification on Android devices.
Granular Security Verification for Android Applications
The new libraries enable applications to query the security status of specific parts of the Android software stack rather than relying on a single date-based patch level. According to the Android Developers Blog, developers can now track patch levels across three distinct areas: the core Android operating system, modular system components updated via Google Play, and the device kernel. By surfacing this data, Google aims to give developers and enterprises the ability to identify missing patches and take proactive remediation steps based on the actual state of the device.
Three Patch Levels for Component Assessment
The Security State library introduces three specific patch levels to provide a comprehensive view of a device’s security status. The Device SPL (DSPL) represents the security patch level currently installed and running on the device, which can be queried without network access. The Published SPL (PSPL) reflects the latest patch level officially documented in the Android Security Bulletin. Finally, the Available SPL (ASPL) identifies the patch level ready for download and installation on the specific device, retrieved through inter-process communication with on-device update clients.
Contextual Security Decisions for Developers
These libraries are designed to support security-critical applications, such as those in banking, fintech, and healthcare, as well as Mobile Device Management (MDM) solutions. Instead of a binary approach to device access, developers can use these APIs to make context-aware decisions. For instance, an application can compare the current device patch level against pending updates before authorizing sensitive actions like high-value payments or credential enrollment. If a device is found to be behind on critical security updates, developers can require the user to install the missing patches before proceeding.
Additionally, the isDeviceFullyUpdated()
function helps determine if all available patches have been applied, while createVulnerabilityReportUrl()
generates standardized links to security bulletins and CVE details.

Standardization for OEM Update Clients
To assist OEMs and developers of Over-The-Air (OTA) update clients, Google introduced the Security State Provider library. This companion library standardizes how update availability is communicated to applications. By providing a unified interface, it ensures that an application does not need to distinguish whether an update originates from Google Play, a proprietary OEM client, or Google’s OTA client. This standardization simplifies the development of security-focused apps by removing the need for custom integration with various manufacturer-specific update mechanisms.
Keep reading
