12 Aug 2010
A team at MWR Infosecurity has uncovered a zero-day flaw in the Palm Pre operating system which allows the handset to be used as a bugging device.
Alex Fidgen, director of MWR, told V3.co.uk that a specially crafted text message can subvert Palm's webOS completely.
The flaw allows the phone to be used as a recorder and transmitter for anything within its microphone's range.
"You receive a specially crafted business card and, once you open it, game over," said Fidgen. "We were surprised to find the lack of security architecture we needed to exploit in the way that we did."
Palm's security systems do not use sandboxing in this case, unlike the security precautions seen in Google's code, Fidgen explained.
Palm, now part of HP, did not return requests for comment.
MWR also disclosed a flaw in older versions of the cross-platform WebKit layout tool which could allow an attacker to harvest user log-ins and passwords for sites visited on a handset.
The vulnerability has been fixed in Android 2.2, a Google spokesman told V3.co.uk.
"This is a bug which is not exclusive to Android and that can only be triggered if users visit a malicious web site or access a malicious Wi-Fi network via their mobile phone," he said.
"We are not aware of any users having been affected by this bug to-date, and it has been fixed in the latest version of Android. As always, mobile phone users can protect themselves by only visiting web sites and using Wi-Fi networks they trust."
Latest stories from Communications
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
PHP Developers - Fixed Term Contracts (initially 6 months...
Junior Ruby on Rails Developer - London - Permanent...
A Project Manager is required to join a leading Insurance...
CCIE Network Engineer required with fluent Hungarian...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?