Android Partner Vulnerability Initiative (APVI) will be publicising security issues it finds in third-party Android devices. APVI only applies to vulnerabilities in code that isnt serviced or maintained by Google. Googles plan appears to be to notify vendors before disclosing a flaw, and so far most of the reported flaws appear to have been fixed. With luck, the threat of having a vulnerability publicised will encourage more Android smartphone manufacturers to take greater care squashing bugs before they end up in the hands of unsuspecting consumers.”]
Source: https://grahamcluley.com/google-warns-android-security-holes-vendors-phones/