Android exploit code published
By Tom Brewster,
An attack code, which could be used to exploit a number of different versions of Google’s Android OS, has been published.
The code exploits a flaw in the WebKit browser framework, a vulnerability that has previously been seen in Apple’s Safari browser.
Alert Logic security researcher M.J. Keith was responsible for making the code public last week, noting how it could be used to gain control over certain functions in the OS.
The researcher showed how visiting a website containing the malicious code on an Android 2.1 phone could allow him to run a simple command line shell in the OS, according to reports.
In turn, this would allow the hacker to compromise the OS, although it would not give them complete control as Android sections off its different components from one another.
However, an attacker could still access anything the browser reads.
At the time of publication, Google had not offered any comment on the security researcher’s findings.
While Android 2.2 remained unaffected by this particular attack, less than two-fifths of all Android users have that version.
According to official Google statistics, Android 2.1 is the most used version of the OS, with over 40 per cent running it.
The code went public just days after a Coverity study showed various weaknesses in Android’s central kernel.
A total of 359 flaws were discovered, a quarter of which were ranked as high risk.
Commenting on the report, Gartner vice president and distinguished analyst Nick Jones said Android will never be truly secure as it lacks a central authority to keep it safe.
“Those managed by a single owner such as Apple, Windows Phone 7 and RIM are better able to ensure higher security,” Jones claimed in a blog.
“However even the best of platforms will have weaknesses.”
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





