Advertisement
Promo

Security threats Toolkit

Google Android

Researcher warns of Android phone vulnerability

Elinor Mills CNET News

Published: 13 Feb 2009 09:58 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A researcher who found a security hole in the Android mobile platform in October has found another one he says is serious enough for him to recommend people not use the Android browser until the patch is installed.

Charlie Miller, a principal analyst at consultancy Security Evaluators, said on Thursday that a patch for the vulnerability is available on Google's source-code repository, but has not yet been made available for download onto the phones via the T-Mobile service.

Like the previous hole, the new vulnerability could allow an attacker to take control of the browser remotely, access credentials and install a keystroke logger if the Android user visits a malicious web page.

"All the gory details are out there and they still haven't patched it," he said, adding that he recommends Android users avoid browsing the web until they have patched their phones.

Android security engineer Rich Cannings said PacketVideo developed a fix for the vulnerability on 5 February and patched Open Source Android two days later. Google offered the patch to T-Mobile when it became available, and G1 Android users "will be updated at T-Mobile's discretion", he said in a statement.

The bug was found in code that was not written by Google but was contributed by multimedia software company PacketVideo to the open-source Android project. PacketVideo's OpenCore media library is used in the mediaserver and is executed within its own Application Sandbox, according to Google.

"Media libraries are extremely complex and can lead to bugs, so we designed our mediaserver, which uses OpenCore, to work within its own application sandbox so that security issues in the mediaserver would not affect other applications on the phone such as email, the browser, SMS and the dialler," Cannings wrote. "If the bug Charlie reported to us on 21 January is exploited, it would be limited to the mediaserver and could only exploit actions the mediaserver performs, such as listen to and alter some audio and visual media."

T-Mobile representatives were unavailable for comment.

Miller, who presented a talk on the Android vulnerability at the Shmoocon security conference in Washington, DC, on Saturday, said he notified Google about 17 days before he gave the talk.

"By comparison, when we found the bug in October in Android, they fixed it in 12 days [with a patch available for the phones]", he said. "They have it in their power to do this quickly."

A year ago at CanSecWest, Miller and colleagues hacked a MacBook Air in two minutes by exploiting a Safari vulnerability. And in 2007, Miller and colleagues discovered an iPhone security hole.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
3 out of 3 people found this useful


Full Talkback thread

0 comments

More in this Special Report

Photos: A rough guide to mobile open source

Photos: A rough guide to mobile open source

Android is not the only open platform. Here's a quick guide to the mobile, open-source landscape more

Analysis: Android may spread beyond phones

Analysis: Android may spread beyond phones

One influential partner backing the open-source operating system has said the software will start to show up in consumer electronics and cars, too more

Photos: A taste of Android 'Cupcake' from the Magic phone

Photos: A taste of Android 'Cupcake' from the Magic phone

ZDNet UK has been given a sneak preview of Vodafone's exclusive HTC Magic handset, the first to use the updated 'Cupcake' version of the Android mobile platform more

Samsung Android phone due in June

Samsung Android phone due in June

O2 Germany has confirmed it will carry Samsung's i7500, which is likely to be the first non-HTC Android phone to be released in Europe more

Analysis: First Android phone enters the smartphone fray

Analysis: First Android phone enters the smartphone fray

The first Google Android phone sports a raft of mobile web features, but how will it stack up against the rest of the crowded smartphone market? more

Photos: T-Mobile G1 (HTC Dream)

Photos: T-Mobile G1 (HTC Dream)

Take a tour of the first Google Android smartphone more

How Android stands out in the smartphone space

How Android stands out in the smartphone space

ZDNet.com's Sumi Das and Sam Diaz discuss whether Google's Android is an iPhone killer and how the technology may eventually reach beyond phones and land inside other products more

Android in action on T-Mobile's G1

Android in action on T-Mobile's G1

At the launch of the G1, a representative of the mobile operator demonstrated how the phone and Android operating system work more

Roundup: First Google Android phone unveiled

Roundup: First Google Android phone unveiled

Unveiling the first handset to use the Android platform, Google hopes to provide a viable alternative to the current crop of largely proprietary mobile platforms more

T-Mobile G1 (HTC Dream) review

T-Mobile G1 (HTC Dream) review

The design isn't great and we'd have liked some additional features, but the real beauty of the T-Mobile G1 is the Google Android platform, as it has the potential to make smartphones more personal and powerful more

Google shares Android source code

Google shares Android source code

The search giant has begun to share the project's underlying source code on the Android Open Source Project site more

Coders to profit as Android Market opens

Coders to profit as Android Market opens

With T-Mobile's G1 phone now on sale in the US, Google has opened the Android Market app store, with developers set to receive 70 percent of revenue more

Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters