The new patchfixes both the original security hole named after researcher Juan Carlos Garcia Cuartango and a recently discovered variant of the problem.
The patch also fixes a bug discovered earlier this month that allows anyone who gains physical access to a phone to bypass its lockscreen in seconds and access contacts and photos.
And Google has been slow to patch those vulnerabilities in Android, Oberheide says, often pushing out fixes to just a segment of users as a test before fully patching phones weeks later.