GoogleがAndroid向けセキュリティーパッチ2023年3月分を案内!

Googleは6日(現地時間)、スマートフォン(スマホ)など向けプラットフォーム「Android」における月次セキュリティーパッチの2023年3月分を告示しています。またGoogleは13日(現地時間)、同社が開発・販売するスマホ「Pixel」ブランドのスマホにおいて2023年3月分のソフトウェア更新を同日より提供開始しており、来週にかけて順次提供されるとのこと。

ソフトウェア更新はネットワーク経由によるアップデート(OTA)が配信開始されているほか、ファクトリーイメージも公開されており、対象となる「Pixel 7」および「Pixel 7 Pro」、「Pixel 5a (5G)」、「Pixel 5」、「Pixel 4a (5G)」、「Pixel 4a」では無料で実施できます。なお、現時点では「Pixel 6a」や「Pixel 6」、「Pixel 6 Pro」といったPixel 6シリーズは含まれていません。

更新後のビルド番号はカナダ向けのPixel 4aが「TQ1A.230205.001.B2」、オーストラリアのTelstra向けのPixel 7とPixel 7 Proが「TQ1A.230205.001.A2」、アメリカのT-MobileとGoogle Fi向けの全機種が「TQ1A.230205.001.D2」、日本を含むそれ以外が「TQ1A.230205.002」となっています。なお、このソフトウェア更新にはセキュリティーパッチのほか、すでに紹介しているようにPixelスマホやスマートウォッチ「Pixel Watch」向けの新機能新機能「Pixel Feature Drop」の第11弾(2023年3月分)も含まれています。

さらに非常に多くの不具合修正や機能改善が含まれており、Pixel 7やPixel 7 ProではeSIMを2つ設定したデュアルSIMデュアルスタンバイ(DSDS)に対応したり、Pixel 7やPixel 7 Proにて特定の状況での指紋認識と応答速度をより改善したり、ソフトウェア更新後にアプリ固有のバッテリー制限設定がリセットされることがある問題などが修正されていたりするいうことです。


Pixelシリーズにはセキュリティーパッチや不具合を修正するソフトウェア更新が毎月提供されており、今月分のセキュリティーパッチはAndroid向けではCriticalが4個、Highが52個、分類なしが5個の合計61個、Pixel向けではCriticalが7個、Highが5個、Moderateが108個の合計120個となっています。またセキュリティー更新以外のPixelシリーズにおける更新内容は以下の通り。

なお、Pixel 7やPixel 7 Proなどを販売するKDDIおよび沖縄セルラー電話の携帯電話サービス「au」やソフトバンクの携帯電話サービス「SoftBank」でもそれぞれソフトウェア更新の提供開始をお知らせしており、auでは更新ファイルサイズと更新時間はPixel 7 Proが約470MB〜2.3GBと約40分、Pixel 7が約460MB〜2.3GBと約40分、Pixel 5が約260MB〜1.9GBと約40分となっており、現時点ではGoogleと同様にPixel 6シリーズについての案内はないため、まだ配信開始されていないようです。

What’s included
In addition to new features, the March 2023 software update for Pixel devices includes several fixes and improvements across several areas, including device stability, connectivity, performance and more - see below for some notable improvements.

Apps
- Fix for issue causing Live Translate feature to prompt for translation too frequently in certain apps *[1]
- Fix for issue occasionally keeping display on while certain app activities are active
- Fix for issue occasionally preventing screenshots from being captured in certain apps
- Fix for issue occasionally preventing Wallpaper & style settings to open

- Battery & Charging
- Fix for issue occasionally causing app-specific battery restriction settings to be reset after a software update
- Fix for issue occasionally preventing Battery Share from charging certain devices or accessories *[2]
- General improvements for charging, battery usage or performance in certain conditions *[1]
- General improvements for wireless charging stability or performance in certain conditions *[2]

Biometrics
- Additional improvements for fingerprint recognition and response in certain conditions *[1]

Bluetooth
- Fix for issue occasionally preventing Android Auto to connect wirelessly with certain vehicle head units
- Improvements for connection stability with certain Bluetooth LE headsets or accessories

Camera
- General improvements for camera stability and performance in certain conditions *[1]
- Improvements for color accuracy or exposure level while using the front camera in certain conditions *[3]

Display & Graphics
- Fix for issue occasionally causing display flicker or artifacts in certain apps or conditions *[1]
- Fix for issue occasionally causing instability or playback errors with certain media apps or content *[1]
- Fix for issue occasionally causing video preview to flicker in certain apps *[1]

Framework
- Fix for issue occasionally preventing keyboard from displaying in certain apps or conditions

Sensors
- Additional tuning for haptics intensity and response in certain conditions *[4]
- General improvements for adaptive brightness response in certain conditions

System
- Fix for issue preventing device bootloader from being unlocked in certain conditions *[4]
- Fix for issue preventing device from booting to Android in certain conditions *[4]
- General improvements for system stability and performance in certain conditions
- Kernel updates to 4.14.295 *[5], 4.19.261 *[6], 5.10.149 *[1]

Telephony
- General improvements for network connection stability and performance in certain conditions

Touch
- General improvements for touch response and performance in certain conditions *[3]

User Interface
- Fix for issue causing certain on-device search results to launch apps in work profile
- Fix for issue causing certain text entries in Battery Usage settings to overlap each other while scrolling
- Fix for issue causing home screen UI to appear blurred in certain conditions
- Fix for issue causing lag or delay with switching between apps while third-party launcher apps are in use
- Fix for issue occasionally causing inner launcher icons to appear clipped after closing a folder
- Fix for issue occasionally causing input text to overlap inside search bar
- Fix for issue occasionally causing media player notification to appear cut off or trimmed
- Fix for issue occasionally causing navigation UI to display over Assistant interface
- Fix for issue occasionally causing notification drawer to appear empty or blank
- Fix for issue occasionally causing Overview screen panels to display over home screen
- Fix for issue occasionally causing Quick Settings tiles to be activated while menu is not pulled down
- Fix for issue occasionally causing screen unlock to overlap with notifications, home screen or other UI elements
- Fix for issue occasionally causing silent mode icon to appear hidden or missing from status bar
- Fix for issue occasionally preventing app icon size to scale correctly when changing display size
- Fix for issue occasionally preventing screenshot sharing or editing to work when tapping overlay buttons
- Fix for issue preventing haptic feedback when interacting with notification drawer in certain conditions
- General improvements for performance in certain UI transitions and animations
- Improvements for home screen icon behavior when switching between different grid sizes
- Improvements for status bar layout and response in certain device orientations

Wi-Fi
- General improvements for Wi-Fi network connection stability & performance in certain conditions
- Improvements for connection stability with certain Wi-Fi 6E-capable routers or networks *[1]

---------------------------------------------------------------
Device Applicability
Fixes are available for all supported Pixel devices unless otherwise indicated below.

*[1] Included on Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro
*[2] Included on Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro
*[3] Included on Pixel 7, Pixel 7 Pro
*[4] Included on Pixel 6a
*[5] Included on Pixel 4a
*[6] Included on Pixel 4a (5G), Pixel 5, Pixel 5a (5G)


<Android Security Bulletin-March 2023>
CVESeverityComponentSubcomponent/TypeUpdated AOSP versions
CVE-2023-20906HighFrameworkEoP11、12、12L、13
CVE-2023-20911HighFrameworkEoP11、12、12L、13
CVE-2023-20917HighFrameworkEoP11、12、12L、13
CVE-2023-20947HighFrameworkEoP12、12L、13
CVE-2023-20963HighFrameworkEoP11、12、12L、13
CVE-2023-20956HighFrameworkID12、12L、13
CVE-2023-20958HighFrameworkID13
CVE-2023-20964HighFrameworkDoS12、12L、13
CVE-2023-20951CriticalSystemRCE11、12、12L、13
CVE-2023-20954CriticalSystemRCE11、12、12L、13
CVE-2023-20926HighSystemEoP12、12L、13
CVE-2023-20931HighSystemEoP11、12、12L、13
CVE-2023-20936HighSystemEoP11、12、12L、13
CVE-2023-20953HighSystemEoP13
CVE-2023-20955HighSystemEoP11、12、12L、13
CVE-2023-20957HighSystemEoP11、12、12L
CVE-2023-20959HighSystemEoP13
CVE-2023-20960HighSystemEoP12L、13
CVE-2023-20966HighSystemEoP11、12、12L、13
CVE-2022-4452HighSystemID13
CVE-2022-20467HighSystemID11、12、12L、13
CVE-2023-20929HighSystemID13
CVE-2023-20952HighSystemID11、12、12L、13
CVE-2023-20962HighSystemID13
CVE-2022-20499HighSystemDoS12、12L、13
CVE-2023-20910HighSystemDoS11、12、12L、13
CVE-2023-20956Google Play system updatesMedia Codecs
CVE-2023-20947Google Play system updatesPermission Controller
CVE-2023-20929Google Play system updatesTethering
CVE-2022-20499Google Play system updatesWiFi
CVE-2023-20910Google Play system updatesWiFi
CVE-2021-33655HighKernelEoP/Frame Buffer
CVE-2023-20620HighMediaTek componentsadsp
CVE-2023-20621HighMediaTek componentstinysys
CVE-2023-20623HighMediaTek componentsion
CVE-2022-47459HighUnisoc componentsKernel
CVE-2022-47461HighUnisoc componentssystem
CVE-2022-47462HighUnisoc componentssystem
CVE-2022-47460HighUnisoc componentsKernel
CVE-2022-22075HighQualcomm componentsDisplay
CVE-2022-40537HighQualcomm componentsBluetooth
CVE-2022-40540HighQualcomm componentsKernel
CVE-2022-33213CriticalQualcomm componentsClosed-source component
CVE-2022-33256CriticalQualcomm componentsClosed-source component
CVE-2022-25655HighQualcomm componentsClosed-source component
CVE-2022-25694HighQualcomm componentsClosed-source component
CVE-2022-25705HighQualcomm componentsClosed-source component
CVE-2022-25709HighQualcomm componentsClosed-source component
CVE-2022-33242HighQualcomm componentsClosed-source component
CVE-2022-33244HighQualcomm componentsClosed-source component
CVE-2022-33250HighQualcomm componentsClosed-source component
CVE-2022-33254HighQualcomm componentsClosed-source component
CVE-2022-33272HighQualcomm componentsClosed-source component
CVE-2022-33278HighQualcomm componentsClosed-source component
CVE-2022-33309HighQualcomm componentsClosed-source component
CVE-2022-40515HighQualcomm componentsClosed-source component
CVE-2022-40527HighQualcomm componentsClosed-source component
CVE-2022-40530HighQualcomm componentsClosed-source component
CVE-2022-40531HighQualcomm componentsClosed-source component
CVE-2022-40535HighQualcomm componentsClosed-source component

<Pixel Update Bulletin-March 2023>
CVESeverityComponentSubcomponent/TypeUpdated AOSP versions
CVE-2023-21000ModerateFrameworkRCE13
CVE-2022-20532ModerateFrameworkEoP13
CVE-2022-20542ModerateFrameworkEoP13
CVE-2023-20971ModerateFrameworkEoP13
CVE-2023-20993ModerateFrameworkEoP13
CVE-2023-21017ModerateFrameworkEoP13
CVE-2023-21028ModerateFrameworkID13
CVE-2023-21029ModerateFrameworkID13
CVE-2023-21031ModerateFrameworkID13
CVE-2023-20996ModerateFrameworkDoS13
CVE-2023-20997ModerateFrameworkDoS13
CVE-2023-20998ModerateFrameworkDoS13
CVE-2023-20999ModerateFrameworkDoS13
CVE-2023-21026ModerateFrameworkDoS13
CVE-2023-20975ModerateSystemEoP13
CVE-2023-20976ModerateSystemEoP13
CVE-2023-20985ModerateSystemEoP13
CVE-2023-20994ModerateSystemEoP13
CVE-2023-20995ModerateSystemEoP13
CVE-2023-21001ModerateSystemEoP13
CVE-2023-21002ModerateSystemEoP13
CVE-2023-21003ModerateSystemEoP13
CVE-2023-21004ModerateSystemEoP13
CVE-2023-21005ModerateSystemEoP13
CVE-2023-21015ModerateSystemEoP13
CVE-2023-21018ModerateSystemEoP13
CVE-2023-21020ModerateSystemEoP13
CVE-2023-21021ModerateSystemEoP13
CVE-2023-21022ModerateSystemEoP13
CVE-2023-21024ModerateSystemEoP13
CVE-2023-21030ModerateSystemEoP13
CVE-2023-21034ModerateSystemEoP13
CVE-2023-21035ModerateSystemEoP13
CVE-2022-40303ModerateSystemID13
CVE-2023-20968ModerateSystemID13
CVE-2023-20969ModerateSystemID13
CVE-2023-20970ModerateSystemID13
CVE-2023-20972ModerateSystemID13
CVE-2023-20973ModerateSystemID13
CVE-2023-20974ModerateSystemID13
CVE-2023-20977ModerateSystemID13
CVE-2023-20979ModerateSystemID13
CVE-2023-20980ModerateSystemID13
CVE-2023-20981ModerateSystemID13
CVE-2023-20982ModerateSystemID13
CVE-2023-20983ModerateSystemID13
CVE-2023-20984ModerateSystemID13
CVE-2023-20986ModerateSystemID13
CVE-2023-20987ModerateSystemID13
CVE-2023-20988ModerateSystemID13
CVE-2023-20989ModerateSystemID13
CVE-2023-20990ModerateSystemID13
CVE-2023-20991ModerateSystemID13
CVE-2023-20992ModerateSystemID13
CVE-2023-21006ModerateSystemID13
CVE-2023-21007ModerateSystemID13
CVE-2023-21008ModerateSystemID13
CVE-2023-21009ModerateSystemID13
CVE-2023-21010ModerateSystemID13
CVE-2023-21011ModerateSystemID13
CVE-2023-21012ModerateSystemID13
CVE-2023-21013ModerateSystemID13
CVE-2023-21014ModerateSystemID13
CVE-2023-21019ModerateSystemID13
CVE-2023-21025ModerateSystemID13
CVE-2023-21027ModerateSystemID13
CVE-2023-21032ModerateSystemID13
CVE-2023-21016ModerateSystemDoS13
CVE-2023-21033ModerateSystemDoS13
CVE-2022-42498CriticalPixelRCE/Cellular firmware
CVE-2022-42499CriticalPixelRCE/modem
CVE-2023-21057CriticalPixelRCE/Cellular firmware
CVE-2023-21058CriticalPixelRCE/Cellular firmware
CVE-2023-24033CriticalPixelRCE/Modem
CVE-2023-21041CriticalPixelEoP/GSC
CVE-2022-42528CriticalPixelID/TF-A
CVE-2023-21054HighPixelRCE/Modem
CVE-2023-21040HighPixelEoP/Bluetooth
CVE-2023-21065HighPixelEoP/libfdt
CVE-2023-21036HighPixelID/Markup
CVE-2023-21067HighPixelID/GPS
CVE-2022-42500ModeratePixelEoP/Telephony
CVE-2023-21038ModeratePixelEoP/Cs40l25 haptic driver
CVE-2023-21042ModeratePixelEoP/LWIS
CVE-2023-21043ModeratePixelEoP/LWIS
CVE-2023-21050ModeratePixelEoP/libexynosdisplay
CVE-2023-21051ModeratePixelEoP/exynos
CVE-2023-21052ModeratePixelEoP/libril_sitril
CVE-2023-21055ModeratePixelEoP/cpif
CVE-2023-21056ModeratePixelEoP/lwis
CVE-2023-21062ModeratePixelEoP/rild_exynos
CVE-2023-21063ModeratePixelEoP/rild_exynos
CVE-2023-21064ModeratePixelEoP/rild_exynos
CVE-2023-21068ModeratePixelEoP/Fastboot startup screen
CVE-2023-21069ModeratePixelEoP/bcm4389 driver
CVE-2023-21070ModeratePixelEoP/bcm4389 driver
CVE-2023-21071ModeratePixelEoP/bcm4389 driver
CVE-2023-21072ModeratePixelEoP/bcm4389 driver
CVE-2023-21073ModeratePixelEoP/bcm4389 driver
CVE-2023-21075ModeratePixelEoP/bcmdhd driver
CVE-2023-21076ModeratePixelEoP/bcmdhd driver
CVE-2023-21077ModeratePixelEoP/bcm4389 driver
CVE-2023-21078ModeratePixelEoP/bcm4389 driver
CVE-2023-21079ModeratePixelEoP/bcm4389
CVE-2023-21039ModeratePixelID/dumpstate
CVE-2023-21044ModeratePixelID/libvendorgraphicbuffer
CVE-2023-21045ModeratePixelID/CPIF
CVE-2023-21046ModeratePixelID/Camera HAL
CVE-2023-21047ModeratePixelID/Camera HAL
CVE-2023-21048ModeratePixelID/WiFi
CVE-2023-21049ModeratePixelID/Camera
CVE-2023-21053ModeratePixelID/SMS
CVE-2023-21059ModeratePixelID/Cellular firmware
CVE-2023-21060ModeratePixelID/SMS
CVE-2023-21061ModeratePixelDoS/Wifi
CVE-2022-25712ModerateQualcomm componentsCamera
CVE-2022-33245ModerateQualcomm componentsWLAN
CVE-2022-33260ModerateQualcomm componentsClosed-source component
CVE-2022-40518ModerateQualcomm componentsClosed-source component
CVE-2022-40519ModerateQualcomm componentsClosed-source component


記事執筆:memn0ck


■関連リンク
・エスマックス(S-MAX)
・エスマックス(S-MAX) smaxjp on Twitter
・S-MAX - Facebookページ
・Pixelシリーズ 関連記事一覧 - S-MAX
・Android Security Bulletin-March 2023  |  Android Open Source Project
・Pixel Update Bulletin-March 2023  |  Android Open Source Project
・Google Pixel Update - March 2023 - Google Pixel Community
・Google Pixel 7 Pro(グーグル ピクセル セブン プロ) アップデート情報 | 製品アップデート情報 | au
・Google Pixel 7(グーグル ピクセル セブン) アップデート情報 | 製品アップデート情報 | au
・Google Pixel 5(グーグル ピクセル ファイブ) アップデート情報 | 製品アップデート情報 | au
・Google Pixel 7、Google Pixel 7 Proをご利用中のお客さまへ(2023年3月14日) | スマートフォン・携帯電話 | ソフトバンク
・Google Pixel 5a(5G)をご利用中のお客さまへ(2023年3月14日) | スマートフォン・携帯電話 | ソフトバンク
・Google Pixel 4a(5G)、Google Pixel 5をご利用中のお客さまへ(2023年3月14日) | スマートフォン・携帯電話 | ソフトバンク
・Google Pixel 4aをご利用中のお客さまへ(2023年3月14日) | スマートフォン・携帯電話 | ソフトバンク
・Android | 可能性を推し進めるプラットフォーム