Google Android Security Flaw Exposed

A serious security flaw has been found in Google’s T-Mobile G1 phone - less than a week after launch.

The vulnerability, discovered by security experts at Baltimore firm Independent Security Evaluators, could potentially allow hackers to direct G1 users to malicious websites.

The G1 runs on Google’s new Android operating system, an open source solution which has been specifically designed for mobile devices. According to Independent Security Evaluators (ISE), a buffer overflow problem with the software leaves users open to serious security breaches.

Once a device is breached, hackers could access any information held within its browser - including cookies and saved passwords - meaning bank details and other personal data could be at risk.

“If you end up on a bad guys’ site, he can basically take over the phone and run code, and access anything your browser has access to and do anything your browser could do,” commented Charlie Miller, principal analyst at ISE.

Although hackers would have access to the browser of a compromised phone, the modular nature of the Android operating system means that other functions, such as voice calling, would be unaffected.

“We wanted to sandbox every single application because you can’t trust any of them,” said Rich Cannings, a security engineer for Google, adding that the company was working on a fix for the problem.

ISE notified Google of the exploit on 20th October - two days before the G1 was released in the US - so that a fix could be worked on before an exploit was found ‘in the wild’. There are currently no reports of hackers taking advantage of the exploit.

Google will correct the security flaw to their iPhone competitor using an over-the-air update shortly. They will also hope that the scare will not harm sales during the all important Christmas retail period.

“We treat all security matters seriously and will carefully work with our partners to investigate and update devices periodically to reduce our users’ exposure,” the company said in a statement.

Comments are closed.

For information about SEO in English, SEO in Chinese, conversion rate optimisation or our software development services contact us now

 

Take advantage of a first rate service backed by years of experience, solid guarantees and UK government accreditation

We pride ourselves on our reputation for delivering top quality IT solutions. It’s why our large portfolio of satisfied clients keeps coming back.

As an associate company member of the prestigious Lancaster University InfoLab21 Knowledge Business Centre, our in-house team has access to resources at the cutting edge of information technology.

Find out how you could benefit from a high quality service tailored exactly to your needs. Talk to us now. No pressure, no obligation.

Enquire Now
Company Name:
Contact Name:
Position in company:
Company Email:
Company website address:
Company Telephone:
From which country or
state are you?

(This helps us contact you in
your own time zone)
My interest is in the following service:
Spam protection - enter the code shown:

(Change verification code)

Submit now for a direct response.

 

Direct Line:
01524 65533

UK Local Call (24/7):
0845 057 3371

US Freephone:
1 877 413 1158

Email Us

| Email Us Valid CSS! Valid XHTML 1.0 Strict