Advertisement
Promo

Mobile devices Toolkit

Google Android

Google fixes Android root-access flaw

David Meyer ZDNet.co.uk

Published: 10 Nov 2008 17:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A bug has been found in Google's Android mobile platform that allows command-line instructions to be automatically run with root privileges.

The bug was revealed late last week, and Google told ZDNet UK on Monday that it had already developed a fix. The operator T-Mobile has, however, not yet said when it will be pushing the update out to users of its G1 handset — the first and, thus far, only handset to use the Android software stack.

"We've been notified of this issue and have developed a fix," Google's spokesperson said. "We are currently working with our partners to push the fix out and are updating the source code base to reflect these changes."

The flaw means any recognisable command line can be run from applications in Android phones that are not using the latest firmware. It also effectively means Android has been reading and automatically interpreting and acting upon inputted text. For example, a commentator on the bug thread on Android's forums noted that a text conversation unexpectedly led to their phone being rebooted.

"I was in the middle of a text conversation with my girl when she asked why I hadn't responded," wrote 'jdhorvat'. "I had just rebooted my phone and the first thing I typed was a response to her text which simply stated 'Reboot' — which, to my surprise, rebooted my phone."

Google's spokesperson told ZDNet UK that the issue had come to light as the company was working on a fix to stop users 'jailbreaking' (making it possible to use another operator's SIM card on) their T-Mobile G1 handsets. The spokesperson added that Google had not received any reports of the issue being exploited.

According to the forum thread, the issue is only to be found in firmware versions prior to the current version, RC30.

This latest flaw follows another highly publicised vulnerability in the Android browser that could have made it possible for users to be tricked into visiting malware-laden websites. Google has since patched that flaw as well.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 10 people found this useful


Full Talkback thread

0 comments

More in this Special Report

Photos: A rough guide to mobile open source

Photos: A rough guide to mobile open source

Android is not the only open platform. Here's a quick guide to the mobile, open-source landscape more

Analysis: Android may spread beyond phones

Analysis: Android may spread beyond phones

One influential partner backing the open-source operating system has said the software will start to show up in consumer electronics and cars, too more

Photos: A taste of Android 'Cupcake' from the Magic phone

Photos: A taste of Android 'Cupcake' from the Magic phone

ZDNet UK has been given a sneak preview of Vodafone's exclusive HTC Magic handset, the first to use the updated 'Cupcake' version of the Android mobile platform more

Samsung Android phone due in June

Samsung Android phone due in June

O2 Germany has confirmed it will carry Samsung's i7500, which is likely to be the first non-HTC Android phone to be released in Europe more

Analysis: First Android phone enters the smartphone fray

Analysis: First Android phone enters the smartphone fray

The first Google Android phone sports a raft of mobile web features, but how will it stack up against the rest of the crowded smartphone market? more

Photos: T-Mobile G1 (HTC Dream)

Photos: T-Mobile G1 (HTC Dream)

Take a tour of the first Google Android smartphone more

How Android stands out in the smartphone space

How Android stands out in the smartphone space

ZDNet.com's Sumi Das and Sam Diaz discuss whether Google's Android is an iPhone killer and how the technology may eventually reach beyond phones and land inside other products more

Android in action on T-Mobile's G1

Android in action on T-Mobile's G1

At the launch of the G1, a representative of the mobile operator demonstrated how the phone and Android operating system work more

Roundup: First Google Android phone unveiled

Roundup: First Google Android phone unveiled

Unveiling the first handset to use the Android platform, Google hopes to provide a viable alternative to the current crop of largely proprietary mobile platforms more

T-Mobile G1 (HTC Dream) review

T-Mobile G1 (HTC Dream) review

The design isn't great and we'd have liked some additional features, but the real beauty of the T-Mobile G1 is the Google Android platform, as it has the potential to make smartphones more personal and powerful more

Google shares Android source code

Google shares Android source code

The search giant has begun to share the project's underlying source code on the Android Open Source Project site more

Coders to profit as Android Market opens

Coders to profit as Android Market opens

With T-Mobile's G1 phone now on sale in the US, Google has opened the Android Market app store, with developers set to receive 70 percent of revenue more

Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment

Ion-toting Eee 1201N to hit UK in Janu...

Asus has confirmed its long-rumoured Eee PC 1201N, the first in the company's line of netbooks to use Nvidia's Ion graphics platform. The 1201N will also be one of the first netbooks... More

2 comments

Discussions

CA CA

Well of course...

Tuesday 24 November 2009, 1:34 AM

5 comments
1000215420 1000215420

Regulation & More Civil Servants

Tuesday 24 November 2009, 1:15 AM

5 comments
CA CA

Sounds great but...

Tuesday 24 November 2009, 12:24 AM

1 comment

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters