There’s been yet another flaw found in Android, and this one is pretty scary. In the bug report on the Android site, jdhorvat says he found it by accident, after using his T-Mobile G1 Android phone. He was texting his girlfriend, when the phone locked up and he had to reboot. When it came back up, he explained why he hadn’t replied to her sooner by simply texting her: “reboot.” To his surprise, when he hit enter to send, the phone rebooted, interpreting his text as a command. But wait, it gets worse.
Once the phone rebooted that way, it opened a command shell as root and proceeded to send every keystroke typed from then on straight to that shell. As ZDNet’s Ed Burnette reports:
“Thus every word you typed, in addition to going to the foreground application would be silently and invisibly interpreted as a command and executed with superuser privileges. Wow!”
Fortunately, Google jumped on the problem right away, and Burnette says his phone patched itself over the weekend. Still, with three major flaws reported in less than a month, early Android users must be wondering just how secure their new phones are.




