Bad apps bypasses Android locks

By
Follow google news

Researchers say Google borked bug bounties.

Researchers have disclosed that Android phones can be silently unlocked by malware after Google failed to respond to a private tip off of the flaw.

Bad apps bypasses Android locks

Curesec researchers said the flaw (CVE-2013-6271) in the Jelly Bean operating system meant malicious applications could bypass pin, password and facial recognition locks.

The company said it reported the issue to Google on 11 October and received a response the following day. But after Curesec  asked Google for feedback three times during October and November, it eventually went public on the problem on 27 November.

In an advisory issued last week and updated this Tuesday, the company said: “Curesec disclosed this vulnerability as Google Android Security Team was not responding any more about this issue.”

A Google representative is reported as saying the problem was fixed in Android Kit Kat 4.4. But currently KitKat represents only 1.1 per cent of the current Android user base, according to the latest Developer Dashboard figures.

A Google spokesperson was unable to comment at the time of writing.

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, UK edition
Tags:

Most Read Articles

Researchers detail Bluetooth headphone attack that can hijack smartphones

Researchers detail Bluetooth headphone attack that can hijack smartphones

Patients fret as ManageMyHealth data breach drama plays out

Patients fret as ManageMyHealth data breach drama plays out

Aussie teenager charged with swatting US retailers and educational institutions

Aussie teenager charged with swatting US retailers and educational institutions

Cloudflare DNS reply change crashed Cisco SME switches

Cloudflare DNS reply change crashed Cisco SME switches

Log In

  |  Forgot your password?