search technology reviews, news, features, group tests
Popular Searches:   video , dell , dvd
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Tuesday November 24, 2009 4:01 AM AEST
Skip Navigation LinksPC Authority > News > First Google Android flaws surface
First Google Android flaws surface
NEWS

First Google Android flaws surface

by Shaun Nichols  on Oct 29, 2008
Outdated components leave Android powered handsets vulnerable.
A trio of researchers has disclosed the first security flaw for the Google Android platform and pointed out a fundamental security problem in the open source process.

The vulnerability was discovered by researchers Charlie Miller, Mark Daniel and Jake Honoroff from security testing and analysis firm Independent Security Evaluators.

While the three have elected not to disclose details about the flaw until a fix can be issued, they said that a successful exploit could allow an attacker to retrieve all stored information in the victim's browser.

The researchers praised Android for its secure "sandbox" mode, which limits the scope of attacks by cutting off access to outside components, but they also noted what could become a major security hurdle for Android.

The flaw lies within one of the open-source components used by the Android platform, say the researchers.

"The vulnerability is due to the fact Google did not use the most up-to-date versions of all these packages," the trio said.

"In other words, this particular security vulnerability that affects the G1 phone was known and fixed in the relevant software package, but Google used an older, still vulnerable version."

Because Android relies on some 80 different open-source components, keeping track of security disclosures and bug fixes could prove difficult, potentially leaving the platform open to future attacks.

News of the disclosure comes less than one week after the first Android-powered handset hit the US market in the form of the T-Mobile G1. Other vendors, including Motorola and Kyocera are also said to be poised to unveil Android devices.

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Telstra confirm 30Mbit national network plan - but don't mention the NBN
Telstra has completed the 100Mbit upgrade to their Melbourne cable network and are next planning to get 30Mbit speeds into the rest of the country; but first they'll need to dispel those endless NBN comparisons
 
Red Hat updates with Fedora 12
Red Hat has released the latest version of its Fedora open source operating system and has added new video, virtualisation and networking support..
 
Picking the perfect home entertainment box: Movie downloads come to the Xbox 360
Unmetered download agreements are next the battleground as games consoles follow the Apple TV's lead to support movie download services.
 


 
Intel
 
 
LogMeIn
 
 
Amazing Dell Coupons now available
 
Discover Apple