All the latest UK technology news, reviews and analysis

First Google Android flaws surface

by Shaun Nichols

More from this author

28 Oct 2008

Comment: 1

  • Tweet this
Android handset
Android relies on 80 open-source components

A trio of researchers has disclosed the first security flaw for the Google Android platform and pointed out a fundamental security problem in the open source process.

The vulnerability was discovered by researchers Charlie Miller, Mark Daniel and Jake Honoroff from security testing and analysis firm Independent Security Evaluators.

While the three have elected not to disclose details about the flaw until a fix can be issued, they said that a successful exploit could allow an attacker to retrieve all stored information in the victim's browser.

The researchers praised Android for its secure "sandbox" mode, which limits the scope of attacks by cutting off access to outside components, but they also noted what could become a major security hurdle for Android.

The flaw lies within one of the open-source components used by the Android platform, say the researchers.

"The vulnerability is due to the fact Google did not use the most up-to-date versions of all these packages," the trio said.

"In other words, this particular security vulnerability that affects the G1 phone was known and fixed in the relevant software package, but Google used an older, still vulnerable version."

Because Android relies on some 80 different open-source components, keeping track of security disclosures and bug fixes could prove difficult, potentially leaving the platform open to future attacks.

News of the disclosure comes less than one week after the first Android-powered handset hit the US market in the form of the T-Mobile G1. Other vendors, including Motorola and Kyocera are also said to be poised to unveil Android devices.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

IT Security Specialist Move in2 Solutions /Pre-Sales in 18 mths

IT Security Specialist Move in2 Solutions /Pre-Sales...

SOFTWARE ENGINEER - UNIX C JAVA ORACLE

SOFTWARE ENGINEER - BERKS - to £34k plus package WAREHOUSE...

Senior Project Manager

We currently have a position for a Senior Project Manager...

JAVA DEVELOPER - BERKSHIRE - TO £34k PLUS PACKAGE

JAVA DEVELOPER TRANSPORT MANAGEMENT SYSTEMS / TMS...

To send to more than one email address, simply separate each address with a comma.