The browser in Google’s Android mobile phone OS has another vulnerability that could let a hacker access the browser and its related data. The hack was detailed in a recent story in Forbes.com, where reporter Andy Greenberg picked up on a presentation scheduled for this past weekend’s ShmooCon, an annual gathering of East Coast hackers. The speaker was Charlie Miller, a principal analyst with Independent Security Evaluators, but best know for his high-profile hacks of the first Android phone (T-Mobile’s G1), the iPhone and MacBook Air. The weakness Miller found and exploited is actually contained in code written by PacketVideo. PV is a software company that contributed an open version of its Core multimedia application framework to become the multimedia subsystem for the Android browser. Google says PacketVideo is fixing the problem and Google will send out a patch for T-Mobile users as soon as possible, according to a Google spokesman cited in Greenberg’s story. The vulnerability would let a hacker take remote control of the Android browser. The hacker could pick up passwords and possibly credit card or other data stored by the browser, or track the user’s Website visits. Android’s architecture uses a “sandbox” approach, that would stop malicious code injected into the browser from accessing and taking over other parts of the operating system or applications. But Miller pointed out in the story that Android lacks other security features now standard in rival platforms such as Windows Mobile or Mac OS X: the ability to block malicious code from executing in memory. That feature would have blocked the ability to exploit the new bug, as well as the one Miller discovered last October, a few days after Android was first released.
New hole found in Android’s browser security
Opinion
Feb 10, 20092 mins




