Security researchers say Android is based on outdated open-source compenents that leave it vulnerable to a perviously known and fixed attack
By Nancy Gohring, October 27, 2008
Researchers at Independent Security Evaluators say they’ve discovered a security flaw in the Android browser that could make users of phones with the browser vulnerable to attack. Android, Google’s open-source software that is currently only running on one phone, HTC’s G1, is based on outdated open-source components, the researchers say. As a result, the vulnerability they have discovered was previously known and fixed, but Google didn’t incorporate the fix into Android, they say. The G1 went on sale last Wednesday from T-Mobile USA, and Google published the source code behind Android on Tuesday. Other manufacturers, including Motorola, are expected to also release phones running Android in the future. The researchers also say, however, that the impact of the attack is limited because of Android’s security architecture. An attacker can’t, for example, control functions of the phone such as the dialer.
Read more here –>Link


Twitter
Google