But if I understand it right, it was Google that screwed up this one. I always thought that they were not taking their responsibility as an OS vendor seriously and they should have taken this horse in back of the barn and shot it years ago.
If I was a betting man: some smaller fish in the Android ecosystem practiced exquisitely terrible key management outside an HSM, got burnt, and will have to slip KPMG or Deloitte an extra big kickback if they ever want to see a clean SOC 2 again.