Forget Google's Boasts: Android Is Still Less Secure Than iOS

Google wants you to know that Android device security is getting better, and we agree. But we disagree that it's getting better because Android is (partly) open-source, or that it might rival Apple's iOS in security.

Oreo may be the hero to save Android security. Credit: MariaX/Shutterstock

(Image credit: Oreo may be the hero to save Android security. Credit: MariaX/Shutterstock)

"Android has achieved a strength of protection that now leads the industry," the Android Security 2017 Year in Review report, released today (March 15), states in its opening paragraphs. "With more than 2 billion active Android devices, it's essential that Google provides the best protections for users at scale."

The report touts a lower malware infection rate and higher prices for Android exploits as evidence that Android security is better. It credits swifter implementation of device updates, more secure versions of Android and the deployment of the free Google Play Protect antivirus tool as reasons for the improvement.

But the report doesn't mention some inconvenient facts. Malicious apps still turn up often in the Google Play store. Most device makers update only recent flagship models. Hundreds of millions of Android devices frequent use other app stores, creating a huge repository and testing ground for Android malware. Only about one percent of all devices run Android 8 Oreo, released seven months ago.

Compare this to the situation with iOS. There have been about four or five malicious apps in the wild for non-jailbroken iPhones -- ever. Device updates roll out to all compatible devices immediately, with uptake rates of more than 90 percent. A steady decrease in the number of jailbroken devices that can access unauthorized app stores. A virtual guarantee that any iPhone less than five years old can install and run the latest version of iOS.

MORE: Best Android Antivirus Apps

All of this makes this claim from the Android report, seemingly directed at Apple, ring hollow: "As a global, open-source project, Android has a community of defenders collaboratively locating the deeper vulnerabilities and developing mitigations. This community may be orders of magnitude larger and more effective than a closed-source project of similar scale."

There is one thing that could make Android security much better, and it already exists -- but in less than one percent of Android devices. Called Project Treble, it grants Google the power to push out security updates to devices without the device maker's permission or cooperation.

Project Treble removes the biggest roadblock to better Android security that's ever existed, and puts at least one foot on the same playing field with iOS. (The other foot would be Apple-style control of the Google Play store, which Google seems philosophically opposed to implementing.)

But sadly, your phone may never get Project Treble, even if it's already been updated to Oreo. Only phones that hit the market with Oreo already installed can be guaranteed to be compatible with Project Treble.

That's because Project Treble involves fundamental changes to how the open-source, Google-proprietary, device-maker-proprietary and carrier-proprietary parts of Android work with one another. (Some phones that have updated to Oreo from Nougat, including Google's Pixel 1, do nevertheless support Project Treble. Our friends at Android Police have a handy list of them.)

MORE: The iPhone Won Because Apple Knows We're Morons

The good news is that the next generation of flagship phones is launching with Oreo. The Samsung Galaxy S9 and S9 Plus, which hit the market tomorrow (March 16), are two of them, and so is the Huawei Honor View 10 that's due next week. Other include the Huawei Mate 10 Pro, the Sony Xperia XZ1, and of course the Google Pixel 2 and Pixel 2 XL.

So if your phone does support Project Treble, you're getting the best security that Android has to offer. It's a security posture that's a hell of a lot better than Android has even a couple of years ago. But it's still no match for iOS security.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Android Phones
Google Pixel 9 with Amazon Spring Sale deal tag
The Google Pixel 9 is at its lowest price ever for Amazon Spring Sale — 30% off now
Amazon Spring Sale Galaxy S25
Amazon’s Spring Sale drops the Samsung Galaxy S25 to $734 — its lowest price ever!
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Latest in Opinion
The Amazfit T-Rex 3 shown close-up on a user's wrist with the snorkeling and surfing workout tracking modes displayed; colorful flowers are out of focus in the background
7 reasons why this budget-friendly smartwatch is my new go-to for surfing and swimming
Apple maps logo on iPhone screen
I avoided Apple Maps for trip planning — but these iOS 18 features are changing my mind
Adam Scott in "Severance," now streaming on Apple TV Plus.
'Severance' season 3 officially greenlit — but I may not watch after that season 2 finale
Woman has taped her mouth shut with a blue I shaped mouth tape
I tried I-shaped mouth tape to fall asleep faster but now I'm more tired than ever — here's why
An angled view of the distraction-free desk setup I built around the Oakywood Standing Desk Pro
I built a completely distraction-free desk setup with these 10 gadgets — and now I’m truly locked in
A Samsung DU7200 LED TV on a side table
I'm a TV reviewer — here's the one type of TV I wouldn't buy