• On The Insider: Britney's Bikini-Clad Top 10
February 12, 2009 1:19 PM PST

Android phones await security patch

by Elinor Mills
  • Font size
  • Print
  • 3 comments

(Credit: Android)

A researcher who found a security hole in the Android mobile platform in October has found another one that he says is serious enough for him to recommend people not use the Android browser until the patch is installed.

Charlie Miller, a principal analyst at consultancy Independent Security Evaluators, said on Thursday that a patch for the vulnerability is available on Google's source code repository, but has not yet been made available for download onto the phones via the T-Mobile service.

Like the previous hole, the new vulnerability could allow an attacker to remotely take control of the browser, access credentials, and install a keystroke logger if the Android user visits a malicious Web page.

"All the gory details are out there and they still haven't patched it," he said, adding that he recommends that Android users avoid browsing the Web until they have patched their phones.

Android Security Engineer Rich Cannings said PacketVideo developed a fix for the vulnerability on February 5 and patched Open Source Android two days later. Google offered the patch to T-Mobile when it became available and G1 Android users "will be updated at T-Mobile's discretion," he said in a statement.

The bug was found in code that was not written by Google but was contributed by multimedia software company PacketVideo to the open source Android project. PacketVideo's OpenCore media library is used in the mediaserver and is executed within its own Application Sandbox, according to Google.

"Media libraries are extremely complex and can lead to bugs, so we designed our mediaserver, which uses OpenCore, to work within its own application sandbox so that security issues in the mediaserver would not affect other applications on the phone such as email, the browser, SMS, and the dialer," Cannings wrote. "If the bug Charlie reported to us on January 21st is exploited, it would be limited to the mediaserver and could only exploit actions the mediaserver performs, such as listen to and alter some audio and visual media."

T-Mobile representatives were unavailable for comment.

Miller, who presented a talk on the Android vulnerability at the Shmoocon security conference in Washington, D.C., on Saturday, said he notified Google about 17 days before he gave the talk.

"By comparison, when we found the bug in October in Android, they fixed it in 12 days," with a patch available for the phones, he said. "They have it in their power to do this quickly."

A year ago at CanSecWest, Miller and colleagues hacked a MacBook Air in two minutes by exploiting a Safari vulnerability. And in 2007, Miller and colleagues discovered an iPhone security hole.

Forbes first reported on the new Android hole last week and ReadWriteWeb followed up.

Updated 4 p.m. PST to clarify Google comment that bug is limited to the mediaserver code and not the entire browser.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
by Michael-Martin February 12, 2009 3:19 PM PST
I am assuming this fix is not in the recent RC33 update, correct?

,Michael Martin
http://www.googleandblog.com/
Reply to this comment
by BAMAToNE February 12, 2009 5:37 PM PST
"... adding that he recommends that Android users avoid browsing the Web until they have patched their phones."

Are you kidding!? Use Opera Mini!
Reply to this comment
by sarah_oneill February 18, 2009 12:29 PM PST
It makes you wonder what other flaws are part of this OS. THere's an interesting article <a href="http://www.atelier-us.com/e-business-and-it/article/exposed-android-security-flaw-makes-browsing-dangerous">here</a>.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right