ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    HTC promises over-the-air vulnerability patch

The Taiwanese firm says a fix for a vulnerability in a number of its Android phones is coming.

By Tom Brewster, 4 Oct 2011 at 14:28

HTC

HTC has responded to reports of a security vulnerability in its Android devices by promising to release an over-the-air patch to be delivered by carriers.

The Android Police released information about a flaw which allowed malicious apps to potentially access data including email addresses, GPS locations and phone numbers from users.

It affected any app on affected devices requesting a single android.permission.INTERNET - which is standard procedure for any app that connects to the web or displays ads. That includes hugely popular apps such as Angry Birds.

This app is capable of collecting all kinds of data.

The Android Police said the flaw resided in a logging tool HTC introduced to some of its devices recently, known as HtcLoggers.apk.

“This app is capable of collecting all kinds of data ... and then provide it to anyone who asks for it by opening a local port,” the Android Police said.

“Yup, not just HTC, but anyone who connects to it, which happens to be any app with the INTERNET permission. Ironically, because a given app has the INTERNET permission, it can also send all the data off to a remote server.”

Now HTC has promised to plug the security hole, admitting a malicious app could be created to exploit the vulnerability. The manufacturer said the flaw would do “no harm to customers’ data,” however.

“So far, we have not learned of any customers being affected in this way and would like to prevent it by making sure all customers are aware of this potential vulnerability,” HTC said.

“HTC is working very diligently to quickly release a security update that will resolve the issue on affected devices. Following a short testing period by our carrier partners, the patch will be sent over-the-air to customers, who will be notified to download and install it.”

A host of HTC phones appear to be affected, including the EVO 4G, EVO 3D and the Thunderbolt.

Android phones have increasingly become a target for cyber criminals. An email-stealing Android app will most likely be seen before the end of the year, a security expert recently told IT Pro.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement