Site icon MacDailyNews

Android reeling after two major security failures

“Android security woes got worse on Thursday, with two separate reports of code defects that put millions of end users at risk,” Dan Goodin reports for Ars Technica. “The first involves the update Google released last week fixing a flaw that allowed attackers to execute malicious code on an estimated 950 million phones with nothing more than a maliciously crafted text message.”

“Seven days later, security researchers are reporting that the patch, which has been in Google’s possession since April, is so flawed that attackers can exploit the vulnerability anyway,” Goodin reports. “‘The patch is 4 lines of code and was (presumably) reviewed by Google engineers prior to shipping,’ Jordan Gruskovnjak and Aaron Portnoy, who are researchers with security firm Exodus Intelligence, wrote in a blog post published Thursday. ‘The public at large believes the current patch protects them when it in fact does not.'”

“Separately, researchers from security firm MWR Labs disclosed a flaw that allows malicious apps to break out of the Android security sandbox,” Goodin reports. “The rash of vulnerabilities being reported in Android and the difficulty in getting them installed on end-user devices is taking its toll on the mobile OS.”

Read more in the full article here.

MacDailyNews Take:

Those who’ve settled for pretend iPhones are coming to a sad realization:

If it’s not an iPhone, it’s not an iPhone.

SEE ALSO:
Apple issues iPhone manifesto; blasts Android’s lack of updates, lack of privacy, rampant malware – August 10, 2015
Waiting for Android’s inevitable security Armageddon – August 10, 2015
Android fingerprint sensors aren’t as secure as iPhone’s Touch ID – August 10, 2015
Apple iPhone sees highest switching rate from Android ever recorded – August 10, 2015
This is how Apple’s iPhone kills Android phones – August 7, 2015
Certifi-gate: Hundreds of millions of Android devices vulnerable to stealth unrestricted access – August 7, 2015
Malformed video files can be used to crash half of all Android phones – July 30, 2015
Security journalist: Goodbye, Android, hello Apple iPhone! – July 29, 2015
950 million Android phones can be hijacked by malicious text messages – July 27, 2015
New Android malware strains to top 2 million by end of 2015 – July 1, 2015
Symantec: 1 in 5 Android apps is malware – April 25, 2015
Kaspersky Lab Director: Over 98% of mobile malware targets Android because it’s much, much easier to exploit than iOS – January 15, 2015
Security experts: Malware spreading to millions on Android phones – November 21, 2014
There’s practically no iOS malware, thanks to Apple’s smart control over app distribution – June 13, 2014
F-Secure: Android accounted for 99% of new mobile malware in Q1 2014 – April 30, 2014
Google’s Sundar Pichai: Android not designed to be safe; if I wrote malware, I’d target Android, too – February 27, 2014
Cisco: Android the target of 99 percent of world’s mobile malware – January 17, 2014
U.S. DHS, FBI warn of malware threats to Android mobile devices – August 27, 2013
Android app malware rates skyrocket 40 percent in last quarter – August 7, 2013
First malware found in wild that exploits Android app signing flaw – July 25, 2013
Mobile Threats Report: Android accounts for 92% of all mobile malware – June 26, 2013
Latest self-replicating Android Trojan looks and acts just like Windows malware – June 7, 2013
99.9% of new mobile malware targets Android phones – May 30, 2013
Mobile malware exploding, but only for Android – May 14, 2013
Mobile malware: Android is a bad apple – April 15, 2013
F-Secure: Android accounted for 96% of all mobile malware in Q4 2012 – March 7, 2013
New malware attacks Android phones, Windows PCs to eavesdrop, steal data; iPhone, Mac users unaffected – February 4, 2013

Exit mobile version