The bad news is that Android is still likely affected. Similar to Apple’s ImageIO, Android has a facility called the BitmapFactory that handles image decoding, and of course libwebp is supported. As of today, Android hasn’t released a security bulletin that includes a fix for CVE-2023-4863 – although the fix has been merged into AOSP. To put this in context: if this bug does affect Android, then it could potentially be turned into a remote exploit for apps like Signal and WhatsApp. I’d expect it to be fixed in the October bulletin.
So a no-click device hack?
From what I’m reading, it’s Sony cutting ties with a s* company.
In the open letter they also ask to contact Sony to get refunds, which is not at all how it works. And GamingHeads should be the one giving refunds. They then manage with Sony.
From comments I can read on the website and reddit, it seems that statues were taking a very long time to ship (5 years).
Tho destroying ready to ship products isn’t great either.