GrapheneOS version 2025102200 released
Tags:
- 2025102200 (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, emulator, generic, other targets)
Changes since the 2025100900 release:
- adevtool: add satellite eSIM overlays to avoid the special Skylo eSIM on 9th/10th gen Pixels being listed as a regular eSIM and being possible to erase with the regular eSIM erase functionality
- kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.111
- kernel (6.12): update to latest GKI LTS branch revision including update to 6.12.52
- System Updater: prevent reboot and security preview notifications from timing out after 3 days which is standard behavior since Android 15 QPR1
- System Updater: mark notification permission as fixed to prevent disabling overall notifications, but enable blocking progress, failure and already up to date notification channels
- Sandboxed Google Play compatibility layer: add support for overriding BinderProxy transactions
- Sandboxed Google Play compatibility layer: add support for out-of-band updates to GmsCompatLib
- Vanadium: update to version 141.0.7390.111.0
- Vanadium: update to version 141.0.7390.122.0
- raise emulator super / dynamic partition size due to reaching the limit in some cases
- adevtool: prefer prebuilt AOSP JDK 21
All of the Android 16 security patches from the current November 2025, December 2025 and January 2026 Android Security Bulletins are included in the 2025102201 security preview release. List of additional fixed CVEs:
- Critical: CVE-2025-48593, CVE-2025-48631
- High: CVE-2022-25836, CVE-2022-25837, CVE-2023-40130, CVE-2024-43766, CVE-2025-22420, CVE-2025-22432, CVE-2025-32319, CVE-2025-32348, CVE-2025-48525, CVE-2025-48536, CVE-2025-48555, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2025-48567, CVE-2025-48572, CVE-2025-48573, CVE-2025-48574, CVE-2025-48575, CVE-2025-48576, CVE-2025-48577, CVE-2025-48578, CVE-2025-48579, CVE-2025-48580, CVE-2025-48582, CVE-2025-48583, CVE-2025-48584, CVE-2025-48585, CVE-2025-48586, CVE-2025-48587, CVE-2025-48589, CVE-2025-48590, CVE-2025-48592, CVE-2025-48594, CVE-2025-48596, CVE-2025-48597, CVE-2025-48598, CVE-2025-48600, CVE-2025-48601, CVE-2025-48602, CVE-2025-48603, CVE-2025-48604, CVE-2025-48605, CVE-2025-48609, CVE-2025-48612, CVE-2025-48614, CVE-2025-48615, CVE-2025-48616, CVE-2025-48617, CVE-2025-48618, CVE-2025-48619, CVE-2025-48620, CVE-2025-48621, CVE-2025-48622, CVE-2025-48626, CVE-2025-48628, CVE-2025-48629, CVE-2025-48630, CVE-2025-48632, CVE-2025-48633, CVE-2025-48634
2025100901 provides at least the full 2025-11-01 patch level and the Android 2025-11-05 patch level (Pixel Update Bulletin could have fixes we don't get early) but will remain marked as providing 2025-10-05.
For detailed information on security preview releases, see our post about it.
GrapheneOS security preview releases - GrapheneOS Discussion Forum
GrapheneOS discussion forumGrapheneOS Discussion Forum
daniel:// stenberg:// reshared this.
Gotcha — you're absolutely right 👍
Why do you think AI loves "finding" issues with strcpy in particular? Is it common in other C projects to make mistakes around it or something?
My understanding is that strcpy in c is one of the traditional "unsafe" functions, because it's easy to cause security issues with it. Since it's so well-known, LLM has likely seen it very often in training data.
However, curl is written according to ANSI C for portability, where only strcpy is available - so there's a trade-off LLM's have no capability to deduce.
Vanadium version 141.0.7390.122.0 released
Changes in version 141.0.7390.122.0:
- update to Chromium 141.0.7390.122
A full list of changes from the previous release (version 141.0.7390.111.0) is available through the Git commit log between the releases.
This update is available to GrapheneOS users via our app repository and will also be bundled into the next OS release. Vanadium isn't yet officially available for users outside GrapheneOS, although we plan to do that eventually. It won't be able to provide the WebView outside GrapheneOS and will have missing hardening and other features.
Comparing 141.0.7390.111.0...141.0.7390.122.0 · GrapheneOS/Vanadium
Privacy and security enhanced releases of Chromium for GrapheneOS. Vanadium provides the WebView and standard user-facing browser on GrapheneOS. It depends on hardening in other GrapheneOS reposito...GitHub
ChatGPT's Atlas: The Browser That's Anti-Web - Anil Dash
A blog about making culture. Since 1999.Anil Dash
reshared this
It's just my luck that I publish the Stalwart port last night and today they make a new release
RT: friedcheese.us/objects/8eab3ae…
Sensitive content
AI slop security reports submitted to curl
AI slop security reports submitted to curl. GitHub Gist: instantly share code, notes, and snippets.Gist
curl disclosed on HackerOne: Use of Deprecated strcpy() with...
Step 2: Locate Vulnerable Code in Progress.c ``` # Find exact strcpy usage in tool_progress.c grep -n "strcpy" ./src/tool_progress.c # OUTPUT: # 94: strcpy(r, "--:--:--"); ``` Step 3: Analyze...HackerOne
That last reply that’s just completely ignored the conversation and tone…
Saddens me if anyone is paying out money to these people.
Jaguar Land Rover hack cost UK economy an estimated $2.5 billion, report says
reuters.com/sustainability/boa…
"IT is just a cost center that must be shrunk as much as possible." -- Every C-suit.
kjsapergia@troet.cafe
My wife is away for a few weeks on an elder care visit so I’m wondering: does anybody have any good recommendations for a two player game, ideally that can be played on #iPhone / #iPad or possibly the web?
it can’t be action/arcade because she shrinks from the sight of a video game controller like a vampire reacting to garlic or fire. 
Word games are good. We used to play words with friends, but it became an ad in crusted garbage heap so I’m not particularly inclined to go back to that.
thanks in advance! 
#accessibility #MicrosoftPowerPoint #BlindStudent @mastoblind @main
psl: add versioned public suffix list updates [ci skip] · curl/curl-for-win@a987219
Replacing the public suffix list bundled with libpsl. The original promise / expectation was that libpsl sees regular updates, and a psl update with it, but the latest release is soon to be 2 year...GitHub
theverge.com/tech/804052/ring-…
Ring’s CEO says his cameras can almost ‘zero out crime’ within the next 12 months
Jamie Siminoff’s new book, Ding Dong, explores how his video doorbell startup turned into a home security behemoth.Jennifer Pattison Tuohy (The Verge)
Grenzbahnhof #Probstzella - ein Schandfleck in mehrfacher Hinsicht. Eine Intitiative bemüht sich, das Gebäude als #Denkort zu erhalten.
Sehenswerte drei Minuten von @fexplorer
#DDR
OK. Takže po migraci dat z NB s W10 na NB s W11 mě česká instalace linuxu místo těch W10.
Jenže kterou distribuci? Chci něco s Plasmou 6 a delší podporou ať nemusím řešit upgrade každý půlrok. Takže tentokrát ne Kubuntu - LTS má Plasmu 5 a 25.10. je až moc experimentální.
Takže po krátkém hledání jsem stáhnul #openSUSE Leap 16.
Bude fungovat? Splní očekávání? Zjistíme v následujících dnech 😎
pro příště můžu doporučit Kionite: fedoraproject.org/cs/atomic-de…
Není to LTS, ale upgrade je o kliknutí na jedno tlačítko a rebootu. Zvládne to i moje mamka (opravdu).
Sensitive content
Eight Sleep adds ‘outage mode’ to smart beds after AWS problems left them frozen
theverge.com/news/804289/eight…
Eight Sleep adds ‘outage mode’ to smart beds after AWS problems left them frozen
Eight Sleep devices were bricked by Amazon’s server issues on Monday, with users reporting smart bedsstuck at high temperatures and inclined positions.Jess Weatherbed (The Verge)
Local network is even more inconvenient.
To most people, a router is just "that thing that turns cable internet into wirelesss internet." According to them, the internet in my router is exactly the same as the internet in your router (maybe faster or slower). If they have a some kind of cursed WiFi setup to get reception in a different room that's actually two networks inside one another, they expect all smart tech to still keep working.
Anyway, none of this would have been a problem with IPV6, working UPNP and less security paranoya.
@jackf723 It's P2P as long as it can punch through, but it still relies on centralized servers for coordinating the punching-through part, and as a fallback for when P2P and/or UDP (which is the only protocol you can realistically use over P2P in most network conditions) is unavailable.
See this for more details on what's going on under the hood tailscale.com/blog/how-nat-tra…
How NAT traversal works
Here we cover how we can get through NATs (Network Address Translators) and connect your devices directly to each other, no matter what’s standing between them.David Anderson (tailscale.com)
@jackf723 Yes, do `tailscale ping node_name`, that'll tell you what you're going through.
That's one of the things ICE (no, not that ICE) is good at. It tries using all the IP addresses a node has, both local and global, until it finds one that works or falls back to relaying.
@jackf723 That's not how WiFi works, it always goes through the router. Security / possible firewalls / client isolation are one reason, range is another, no need to establish WPA sessions between devices is yet another.
There's no IP routing though I think, it's all on L2 and ARP / MAC address based I believe.
@jackf723 Ask your favorite LLM about the difference between an access point, a hub, a switch and a router. Those are pretty basic network concepts, a modern large model should have no problems there.
You can also find overviews of course, if you're willing to wade through the blogspam and/or have access to Cisco content.
SuspiciousDuck reshared this.
Sweet dang. re: Omarchy & Framework - “Out of all the Linux distributions out there, this barely configured stack of poorly written Bash scripts on top of Arch is clearly the best choice for us to support!”
Nuclear and Hydro Linked to Lower Electricity Prices. Wind and Solar are Not.
I often hear the phrase “Wind and solar lower electricity prices", but is that really true? I decided to plot the data.
Looking at the average spot market price (no taxes or tariffs) across 30 European countries in 2024, wind and solar seem to have no effect on electricity prices. The weighted regression actually shows a slightly positive slope, meaning prices go up as the share of wind and solar increase, but it is far from statistically significant (R2 = 0.03, p = 0.4).
In short: wind and solar explain nothing about a country’s electricity price.
On the other hand, when looking at clean firm power sources like hydro and nuclear, the explanatory power becomes much stronger.
Using a Weighted Least Squares (WLS) regression across 30 European countries, weighted by total electricity production, there is a clear and statistically significant relationship (R2 = 0.4, p < 0.001). Countries with more hydro and nuclear tend to have lower electricity prices. Of course, this does not explain all the variation, since plenty of other factors matter too.
But it sends a clear signal: hydro and nuclear are linked to cheaper electricity, while wind and solar are not having any measurable effect in either direction.
[Original text by Johan Christian Sollid, as posted on X]
LibreOffice and Google Summer of Code 2025: The results - The Document Foundation Blog
This year, LibreOffice was once again a mentoring organization in the Google Summer of Code (GSoC), a global program focused on bringing more developers into free and open source software development. Seven projects were finished successfully.Ilmari Lauhakangas (The Document Foundation)
reshared this
Is this just importing Markdown or authoring / exporting Markdown too?
One thing I've really wished LO Writer had was a format that exported *plain* HTML / Markdown (e.g., HTML without scads of style gunk).

warmaster
in reply to KindnessInfinity • • •Today I received the invitation to update. It explained the embargo fiasco pretty clearly, and it's well designed in order to influence the user to accept it. But still opt in.
Easy, short and to the point. Great work all around.