Google Releases Stable AndroidX Security State Libraries for Patch Checks
New stable AndroidX libraries allow applications to programmatically assess the security patch status of the system, kernel, and Project Mainline modules.

AndroidX Security State libraries have reached a stable release. Google introduced them on September 17 as a tool that allows applications to programmatically assess the security status of an Android device, including system, kernel, and Project Mainline module patches. According to the official notes, AndroidX Security State 1.1.0 and Security State Provider 1.0.0 were released on September 9, 2026.
The mechanism is intended to help applications, enterprise tools, and MDM platforms work with more detailed data than the Android Security Patch Level date alone provides. Android security fixes arrive through multiple channels, and their status may not be reliably summarized by a single date.
What AndroidX Security State libraries provide
AndroidX Security State provides visibility into the status of installed operating system, kernel, and Project Mainline module patches. It can also indicate that pending updates are available for a device. Applications can check the status of selected CVE identifiers and also account for additional patches supplied by the device manufacturer.
Google’s documentation distinguishes between data about installed patches and updates that are already available but have not yet been installed by the user. This distinction may be relevant, for example, when assessing a device before granting access to sensitive enterprise services or during operations in which an application requires a certain level of security.
Google provides Mainline module update data on devices with GMS services. In the announcement, it also states that GOTA is already integrated.
Security State Provider for manufacturers’ OTA clients
The release includes Security State Provider 1.0.0. It is an interprocess communication (IPC) mechanism through which device manufacturers’ OTA clients can publish information about available system updates to other applications.
This element is important for covering updates handled by the device manufacturer. However, the completeness of system OTA update data will depend on whether a particular OEM integrates its update client with Security State Provider. Google mentions early partners, but the extent of their production deployment was not independently confirmed in the available verified sources.
Why the monthly patch date alone is not enough
Android receives fixes through system updates, kernel updates, and separately updated Project Mainline modules. A device may therefore have different statuses across individual platform components than the monthly Security Patch Level alone would suggest.
A unified API could give enterprises, MDM platforms, and applications handling sensitive operations a more precise basis for deciding whether a device should be granted access. Instead of checking a single date, they can work with information about specific patches, selected CVEs, or pending updates.
However, this is not a fix for a new vulnerability or an announcement of active exploitation. Google introduced infrastructure for assessing patch status, not a new security patch package.
What to watch next
- which Android device manufacturers and OTA client providers deploy support for Security State Provider,
- whether enterprise, financial, and other security-sensitive applications begin evaluating specific CVEs or pending updates,
- feedback on permissions, compatibility, and the reliability of the data provided across different devices.
Sources
- Google Security Blog – On September 17, 2026, Google announced the introduction of the libraries and their intended use for enterprises, OEMs, and security-sensitive applications.
- Android Developers Blog – Confirms the stable versions, the DSPL/PSPL/ASPL model, CVE checks, and the dependence of system OTA data on integrated update clients.
- Android Developers – Security release notes – Confirms the release of Security State 1.1.0 and Security State Provider 1.0.0 on September 9, 2026, and lists their main API functions.
- Android Developers – Understand device security state – Documents the architecture, the difference between installed and available patch status, and Mainline and GOTA coverage.
Verified and updated: 09/18/2026 06:25



