Saturday, January 29, 2011

Android Data Stealing Vulnerability discovered.

Is your android not yet ready to protect your phone data ??? Yes, according to revelation by a security researcher. One researcher found out a way to exploit a loop hole to bypass into your phone and that can be used to steal data.

Xuxian Jiang, an assistant professor at North Carolina State University, discovered the bug while working on what he described as an Android-related project. The flaw, he wrote in an advisory, impacts Android 2.3 and is of the same nature as a vulnerability uncovered last year by researcher Thomas Cannon on Android 2.2.

In an e-mail to eWEEK, Jiang explained that his exploit was not particularly difficult to implement, but requires some knowledge of JavaScript and Android. The issue is mainly in the Android browser, though there is a nonbrowser component in Android that is also related to the vulnerability, he wrote.

Google Android spokeperson interacted with Jiang about the flaw and has developed a fix that will be rolled out in an upcoming Android 2.3 maintenance update.

Temporary you can protect your phone data by, temporarily disabling JavaScript support in the Android browser or using a third-party browser instead, says Jiang

Src: [eWeek]

No comments: