Google’s open-source tool Vanir checks Android platform source code for known security fixes that may be missing. It is intended for Android developers, device makers and maintainers of customized or backported code—not as an app for checking the security of a personal phone.
What Vanir checks
Android fixes are often adapted for vendor-specific branches, older releases and customized kernels. Verifying those backports across many source trees can be labor-intensive. Vanir helps teams check that code by comparing a target source tree with signatures associated with known vulnerable code.
Google describes Vanir as a static analysis tool. Its signature generator creates signatures from vulnerability records that reference security fixes. The detector parses source files, normalizes code blocks and compares their hashes with available signatures. A match is reported as a vulnerability or potentially missing patch. The detector analyzes source code directly rather than relying on version numbers, commit histories, software bills of materials (SBOMs) or build configurations. The official README documents its components and operation.
Google distributes its Android vulnerability signatures through the Open Source Vulnerabilities (OSV) database. The README says Google’s supplied Android signatures cover CVEs published through Android security bulletins since July 2020. Teams can also provide custom JSON signature files, if they have suitable signatures for other feeds or controlled testing.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Who should use it—and who should not
Vanir is for teams with access to Android platform source code: platform developers, OEMs, downstream device or chipset manufacturers, and custom-kernel maintainers. It can help them check whether a known fix appears to be present in a customized tree even when the fix was adapted rather than copied verbatim.
It is not a phone-side scanner. Installing Vanir on a consumer handset will not tell an owner whether the installed operating system is fully patched; the tool needs source code to analyze.
Install and scan a source tree
The README documents a Python package installation and a command-line scan. The example below uses the Android repository name and a local source-tree path:
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Install Vanir:
pip install vanir - Run the detector:
python -m vanir.detector_runner repo_scanner Android ~/my/android/repo - Review the reports: The detector produces JSON and HTML reports with CVE information, paths and functions identified as unpatched, patch references and matched signatures.
For a standalone detector, the README also documents a Bazel build route. Its listed prerequisites include Git and Java 11 or later, along with Bazel compatibility guidance. Check the current README for build details before using that route, since dependencies and version requirements can change.
Choose how Vanir selects files
The repository describes three target-selection strategies. They trade scan breadth and speed against the chance of missing moved code or reporting similar-but-different files:
| Strategy | Trade-off |
|---|---|
ALL_FILES |
Broad and thorough, but slow. The README warns that large scans can take several hours and may produce false positives when files are similar but different. |
EXACT_PATH_MATCH |
Faster, but can miss relevant code that has moved from canonical paths. |
TRUNCATED_PATH_MATCH |
The default compromise, intended to find potentially relevant files in complex trees. |
For a first pass on a complex downstream tree, the default strategy provides a practical starting point. Consider broader selection when the consequences of missing moved code outweigh the added scan time and review effort. Review matches against the target code and patch context, particularly with broad scans.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What published coverage and timing figures mean
Google’s figures are dated publisher statements, not independently reproduced benchmarks. In its December 5, 2024 announcement, the Android Security team said Vanir covered 95% of Android kernel and userspace CVEs with public security patches, and that OSV contained more than 2,000 Android vulnerabilities at the time. Those figures describe the announcement’s scope and date; coverage and database contents can change as signatures are added. The 95% claim does not mean Vanir covers every Android vulnerability or every private fix.
The same announcement estimated 10–20 minutes to scan an entire Android source tree on a modern PC. The repository README, accessed September 30, 2026, describes roughly half an hour to scan one AOSP Android tree on a modern consumer PC. These approximate estimates differ and should not be treated as a guaranteed runtime or a direct benchmark comparison: scan duration depends on tree size, signature set, file selection and environment.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Google also reported that one engineer checked more than 150 vulnerability signatures across downstream branches in five days. That is an illustrative use case, not a general productivity guarantee. See Google’s announcement for these attributed figures.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to interpret a finding
A match means code in the scanned tree resembles a pattern represented by a vulnerability signature. It is a lead for maintainers to review—not proof that a particular shipped device is vulnerable, a complete security assessment, or evidence that every issue is covered. Vanir does not install fixes or provide a complete patching workflow. Its results depend on the available vulnerability records and signatures, and teams must verify findings in the context of their branch and build.
Vanir can run as a Python library and be added to a continuous-integration or build-and-test pipeline. That can make source-tree checks repeatable as code changes; the team still needs to investigate findings and apply or backport fixes through its own maintenance process.
Vanir is different from Android supplemental patch reporting
Android also documents an optional supplemental_security_patches.xml mechanism for OEMs to report CVEs fixed beyond a device’s declared security patch level (SPL). This is a reporting and API integration mechanism, not a source-code scanner like Vanir.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
According to the AOSP documentation updated September 8, 2026, Android 17 (API 37) and higher expose aggregated supplemental patch information through SecurityStateManager. Android 16 and lower can use the Jetpack androidx.security:security-state compatibility library with the documented OEM setup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

