Android handset
Android relies on 80 open-source components

First Google Android flaws surface

Outdated components leave handset vulnerable

Written by Shaun Nichols in San Francisco

A trio of researchers has disclosed the first security flaw for the Google Android platform and pointed out a fundamental security problem in the open source process.

The vulnerability was discovered by researchers Charlie Miller, Mark Daniel and Jake Honoroff from security testing and analysis firm Independent Security Evaluators.

Advertisement

While the three have elected not to disclose details about the flaw until a fix can be issued, they said that a successful exploit could allow an attacker to retrieve all stored information in the victim's browser.

The researchers praised Android for its secure "sandbox" mode, which limits the scope of attacks by cutting off access to outside components, but they also noted what could become a major security hurdle for Android.

The flaw lies within one of the open-source components used by the Android platform, say the researchers.

"The vulnerability is due to the fact Google did not use the most up-to-date versions of all these packages," the trio said.

"In other words, this particular security vulnerability that affects the G1 phone was known and fixed in the relevant software package, but Google used an older, still vulnerable version."

Because Android relies on some 80 different open-source components, keeping track of security disclosures and bug fixes could prove difficult, potentially leaving the platform open to future attacks.

News of the disclosure comes less than one week after the first Android-powered handset hit the US market in the form of the T-Mobile G1. Other vendors, including Motorola and Kyocera are also said to be poised to unveil Android devices.

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols

19 Dec 2008

2.93 MBPodcast Special: Views from the Valley More...

Podcast image

18 Dec 2008

17.6 MBComputing podcast - the highlights of 2008 More...

Shaun Nichols and Iain Thomson

15 Dec 2008

4.98 MBPodcast Special: Views from the Valley More...

Poll

Communications super-database

Communications super-database

Should the government be allowed to track our emails and internet use?

Previous poll results

Spotlight

CES 2009

CES 2009 Special Report

All the latest coverage from Las Vegas   More...

Green lightbulb

Electronics makers urged to go greener

Greenpeace research finds much work still needs to be done   More...

Stressed IT worker

Abused IT workers ready to quit

Research finds a quarter of tech staff looking for a...  More...

Macworld 2009

Macworld 2009 Special Report

All the latest coverage from San Francisco   More...

Primary Navigation