Discussion de forum

Avatar de ndjemhi
ndjemhi
Initiate
09-11-2025
Résolu

When will Videotron deploy the November 1, 2025 Android Security Update?

CRITICAL: Network Signaling Issue Preventing Android Security Updates (Re: CVE-2025-48593 & S25/S20 FE)

Hello,

I am writing to inquire about the planned deployment timeline for the most recent Android Security Bulletin, dated November 1, 2025, and to report a severe, reproducible issue that appears to be preventing prompt security updates for Samsung devices on the Videotron network.

My devices' security patch levels are significantly behind, which is unacceptable given the critical nature of the fixes included in monthly updates. I am specifically looking for information regarding the patch that includes the fix for the vulnerability identified as CVE-2025-48593. While the CVE status is currently Reserved on cve.org, its inclusion in the official bulletin emphasizes the need for a prompt update.

For reference, the official sources for this update are:

  • Google Android Security Bulletin - November 1, 2025: https://source.android.com/docs/security/bulletin/2025-11-01
  • CVE Record for CVE-2025-48593: https://www.cve.org/CVERecord?id=CVE-2025-48593

My Observations & Urgent Questions

I have two Samsung devices exhibiting the same strange behavior, confirming a likely issue with the Videotron network:

  1. Device 1 (Samsung S20 FE): This device is currently stuck on the July 1, 2025 security patch. The industry standard is that the October 1st patch has already been released for this model.
  2. Device 2 (Samsung S25 Flagship): This newer, monthly-supported device was also stuck on the July 1, 2025 security patch. It only found and installed the October 1, 2025 patch after I manually removed Videotron as the network carrier in the phone's settings and then added it back.

Based on this testing, I have two critical questions for the Videotron team:

  1. When is Videotron planning to roll out the November 1, 2025, security patch to its flagship devices? A four-month security gap is a serious security failure, and a clear, confirmed deployment date is required.
  2. Is there a known, systemic issue with how Videotron's network is signaling the latest available security patch to Samsung Android devices? Since two separate phones only received the available update after the network connection was forcibly reset (by removing/re-adding the carrier), this strongly suggests that the automatic, over-the-air (OTA) check triggered by the network is failing to register the update's availability. This affects all users who are simply waiting for the update notification.

I urge the Videotron technical team to investigate this network-level signaling problem immediately. Thank you for your urgent attention to the security of your customers' devices.

Thank you.

  • From what i can see, this situation does not appear to be caused by Videotron. Android security updates are developed and released by the device manufacturer ( Samsung, Google..ect) who manage the entire update cycle. One Samsung finalizes the update for a specifc device model and region, the carrier's role is typically limited to validating and distributing the update. 

    Delays most often occur because the manufacturer has not yet released the update for the corresponded Canadian firmware branch, rather than because the carrier is intentionally blocking or witholding it. Based on this, it is unlikely that Videotron is responsible for the update delay. 

     

    Regards,

1 Réponse

  • From what i can see, this situation does not appear to be caused by Videotron. Android security updates are developed and released by the device manufacturer ( Samsung, Google..ect) who manage the entire update cycle. One Samsung finalizes the update for a specifc device model and region, the carrier's role is typically limited to validating and distributing the update. 

    Delays most often occur because the manufacturer has not yet released the update for the corresponded Canadian firmware branch, rather than because the carrier is intentionally blocking or witholding it. Based on this, it is unlikely that Videotron is responsible for the update delay. 

     

    Regards,