First Android flaws surface

  • Email a Friend
  • Print Page
First Android flaws surface
Oct 28, 2008 3:17 PM
Tags: android | security | components | first | flaw | google

A trio of researchers have disclosed the first security flaw for the Google Android platform and pointed out a fundamental security problem in the open source process.

The vulnerability was discovered by researchers Charlie Miller, Mark Daniel and Jake Honoroff from security testing and analysis firm Independent Security Evaluators.

While the three have elected not to disclose the specifics on the flaw until a fix can be issued, they said that a successful exploit could allow an attacker to retrieve all stored information for the victim's browser.

The researchers credited Android for its use of a secure 'sandbox' mode which limits the scope of attacks by cutting off access to outside components, but they also noted what could become a major security hurdle for Android.

The flaw lies within one of the open-source components used by the Android platform, say the researchers.

"The vulnerability is due to the fact Google did not use the most up to date versions of all these packages," the trio noted.

"In other words, this particular security vulnerability that affects the G1 phone was known and fixed in the relevant software package, but Google used an older, still vulnerable version."

Because Android relies on some 80 different open-source components, keeping track of security disclosures and bug fixes could prove difficult, potentially leaving the platform open to future attacks.

News of the disclosure comes less than one week after the first Android-powered handset hit the US market in the form of the T-Mobile G1. Other vendors, including Motorola and Kyocera are also said to be prepping Android units.

Copyright © 2009 v3.co.uk


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
TIO website hit by malware
Weekend malware runs one new process per target machine.
 
Microsoft announces Azure launch date
Australia in second wave of country releases.
 
CBA embarks on "database-as-a-service"
Analysis: How the bank intends to save megabucks.
 

Spotlightthe topics we're following

Latest Comments

"With Optus supposedly boosting this service sounds great, record profits on mobile business ..."
by Johnnnny Feb 10, 2010 9:58 AM
 
"The Howard government used to provide free net-nanny software that parents could download & ..."
by Ace Feb 10, 2010 9:56 AM
 
"Digger and JL - the two biggest back-flippers in history. (Or are they they same person ?) Now ..."
by marklara Feb 10, 2010 9:56 AM
 
"Once we get past cloud computing, it will be full speed ahead to blue sky computing - although ..."
by Ace Feb 10, 2010 9:52 AM
 
"Maxxi if your reading this I am pretty sure the opinion of Google far outweighs the minority ..."
by Mark D Feb 10, 2010 9:46 AM
1) HTC Magic16 plans 2%
2) Nokia N9743 plans 9%
3) Nokia E7149 plans 1%
4) Apple iPhone 3GS 16GB30 plans 11%
5) Apple iPhone 8GB42 plans 5%
1) iiNet32 plans 5%
2) Netspace36 plans 11%
3) TPG Internet19 plans 14%
4) Optus33 plans 1%
5) Telstra BigPond30 plans 2%

Mobiles | Broadband | Credit Cards

iTnews

Polls

What is the sweet spot for Apple's entry 16GB Wi-Fi iPad?




   |   View results
$549
  77%
 
$579
  11%
 
$619
  4%
 
$649
  3%
 
$699
  5%
TOTAL VOTES: 384

Vote