toggle

AAPL Stock: 123.26 ( + 0.49 )

Printed from http://www.macnn.com

Google fixes Android cryptological app security flaw, updates due soon

updated 09:59 am EDT, Tue July 9, 2013

Fix for four-year vulnerability sent to Android OEMs

Google has plugged a serious security hole in Android, one that potentially allowed for the installation of malware in an APK without breaking an app's cryptographic signature. The flaw, discovered in February, reported to Google and publicly announced last week by mobile security research firm Bluebox Labs, affects versions of Android as far back as version 1.6.

Android apps contain a cryptographic signature which proves to the device's kernel that it has not been altered or otherwise tampered by other parties. As the vulnerability allows the app to be changed without altering the signature, Android will believe it is unmodified, and will run the app as it normally would.

Speaking to ZDNet, Android communications manager Gina Scigliano confirmed "that a patch has been provided to our partners - some OEMs, like Samsung, are already shipping the fix to the Android devices." Considering the typical schedule for updates from manufacturers via carriers, this could be a quick fix for the latest devices, while older generations of smartphone or tablet may end up waiting a considerable amount of time for the update.

While the flaw is potentially serious, it does not appear to have affected apps in general. Scigliant advised that Google has "not seen any evidence of explotation in Google Play or other app stores via our security scanning tools. Google Play scans for this issue, and Verify Apps provides protection for Android users who download apps to their devices outside of Play."




by MacNN Staff

POST TOOLS:

TAGS :

toggle

Comments

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

Follow us on Facebook

toggle

Most Popular

Advertisement

Recent Reviews

15-inch MacBook Pro with Force Touch

Apple's 15-inch Retina MacBook Pro continues to be a popular notebook with professional users and prosumers looking for the ultimate ...

Typo keyboard for iPad

Following numerous legal shenanigans between Typo -- a company founded in part by Ryan Seacrest -- and the clear object of his physica ...

Entry-level 27-inch Retina iMac

The 27-inch Apple iMac with 5K Retina display is already one of the best value-for-money Macs that Apple has ever released. It was som ...

toggle

Most Commented