Google has launched the stable AndroidX Security State version 1.1.0 and Security State Provider version 1.0.0 libraries, enabling applications to perform component-level security verification.
Granular Visibility Replaces Monolithic Patch Dates
Historically, Android devices relied entirely on a single Security Patch Level (SPL) date to reflect the system’s overall defensive posture. That coarse approach no longer fits a platform where critical subsystems update independently through modular channels.
The AndroidX Security State library introduces three distinct patch metrics to solve this fragmentation. The Device SPL tracks the patch level currently installed on the hardware. The Published SPL indicates the latest security level officially released by Google. The Available SPL identifies updates ready to download on that specific device.

These metrics operate across three precise layers:
- System: The foundational core Android operating system managed via standard OEM system OTA updates.
- System modules: Modular subsystems updated dynamically in the background via Google Play system updates under Project Mainline.
- Kernel: The lowest software bridge connecting hardware and OS, evaluated using Long-Term Support release versions such as 5.15.159 or 6.1.91 rather than standard calendar dates.
Enforcing Security Checks in High-Risk Applications
Security-critical software, including banking platforms, healthcare tools, and enterprise Mobile Device Management solutions, can now programmatically inspect device health before executing sensitive tasks. Instead of issuing a hard block when a device falls behind, developers can query pending updates and direct users straight to the necessary installation screen.
Applications can execute synchronous posture checks upon launch by comparing installed versions against published releases. Developers can query specific Common Vulnerabilities and Exposures to verify whether crucial hardware or software fixes—such as Bluetooth or NFC patches—are actively applied before permitting tap-to-pay transactions or proximity data sharing.
Functions like queryAllAvailableUpdates() and fetchAvailableSecurityPatchLevel() aggregate pending updates across various components. Meanwhile, areCvesPatched() scans for targeted vulnerability fixes, and isDeviceFullyUpdated() confirms whether every available patch has been successfully applied.
Standardizing OEM Update Delivery
Alongside the developer-facing library, Google introduced the companion Security State Provider version 1.0.0 library specifically for original equipment manufacturers and over-the-air client developers.
This companion tool establishes a standardized mechanism for update clients to communicate available packages to local apps. Client applications no longer need to check whether an update originates from Google Play, a Google OTA client, or an OEM’s proprietary delivery system.
Related reading