Android exploit code published

Powered by SC Magazine
 

Flaw in WebKit browser framework.

An attack code, which could be used to exploit a number of different versions of Google’s Android OS, has been published.

The code exploits a flaw in the WebKit browser framework, a vulnerability that has previously been seen in Apple’s Safari browser.

Alert Logic security researcher M.J. Keith was responsible for making the code public last week, noting how it could be used to gain control over certain functions in the OS.

The researcher showed how visiting a website containing the malicious code on an Android 2.1 phone could allow him to run a simple command line shell in the OS, according to reports.

In turn, this would allow the hacker to compromise the OS, although it would not give them complete control as Android sections off its different components from one another.

However, an attacker could still access anything the browser reads.

At the time of publication, Google had not offered any comment on the security researcher’s findings.

While Android 2.2 remained unaffected by this particular attack, less than two-fifths of all Android users have that version.

According to official Google statistics, Android 2.1 is the most used version of the OS, with over 40 percent of users running it.

The code went public just days after a Coverity study showed various weaknesses in Android’s central kernel.

A total of 359 flaws were discovered, a quarter of which were ranked as high risk.

Commenting on the report, Gartner vice president and distinguished analyst Nick Jones said Android will never be truly secure as it lacks a central authority to keep it safe.

“Those managed by a single owner such as Apple, Windows Phone 7 and RIM are better able to ensure higher security,” Jones claimed in a blog.

“However even the best of platforms will have weaknesses.”

This article originally appeared at itpro.co.uk

Copyright © ITPro, Dennis Publishing


Android exploit code published
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3085

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 982

Vote