IoT Security

Google Says Android pKVM Earns Highest Level of Security Assurance

Android pKVM has achieved SESIP Level 5 certification, which means it’s resistant to highly skilled, motivated, and funded attackers.

Android vulnerability

Google announced this week that Android’s protected KVM (pKVM) has achieved SESIP Level 5 certification, claiming that it’s the first widely deployed security system to earn this level of assurance.  

The Security Evaluation Standard for IoT Platforms (SESIP) is a security evaluation and certification framework designed for IoT products. SESIP defines five levels, from Level 1, which is based on self assessment, up to Levels 4 and 5, which require a rigorous evaluation. 

“Achieving SESIP Level 5 is a landmark because it incorporates AVA_VAN.5, the highest level of vulnerability analysis and penetration testing under the ISO 15408 (Common Criteria) standard,” Google explained

It added, “A system certified to this level has been evaluated to be resistant to highly skilled, knowledgeable, well-motivated, and well-funded attackers who may have insider knowledge and access.”

pKVM is a security-focused virtualization technology used by Android for confidential computing, ensuring that sensitive data and processes remain protected even if the operating system is compromised. 

The level of protection provided by pKVM can be very useful for organizations developing applications that handle sensitive data. 

Advertisement. Scroll to continue reading.

For users, the SESIP 5 level certification means their personal data, including information processed by on-device AI, is more secure.

Related: Android’s August 2025 Update Patches Exploited Qualcomm Vulnerability

Related: Iranian APT Targets Android Users With New Variants of DCHSpy Spyware

Related: July 2025 Breaks a Decade of Monthly Android Patches

Related: Undetectable Android Spyware Backfires, Leaks 62,000 User Logins

Related Content

Government

UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.

IoT Security

The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks.

Mobile & Wireless

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Mobile & Wireless

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

Malware & Threats

Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.

Mobile & Wireless

CVE-2026-0073 affects Android’s System component and it can be exploited without any user interaction. 

Artificial Intelligence

The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million.

Mobile & Wireless

Offered as a MaaS to a small number of affiliates, mainly Russian speakers, the RAT can turn devices into residential proxy nodes.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version