MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Wed, Dec 03, 2008 - 05:35 PM EST  —  AAPL: 95.90 (+3.43, +3.71%)  |  NASDAQ: 1492.38 (+42.58, +2.94%)

Multiple security vulnerabilities in Google’s Android SDK can give hackers complete control of phone
Thursday, March 06, 2008 - 10:50 AM EST

Core Security Technologies has published a CoreLabs Advisory, "Multiple vulnerabilities in Google's Android SDK" which explains:

Several vulnerabilities have been found in Android's core libraries for processing graphic content in some of the most used image formats (PNG, GIF an BMP). While some of these vulnerabilities stem from the use of outdated and vulnerable open source image processing libraries, otherss were introduced by native Android code that use them or that implement new functionality.

Exploitation of these vulnerabilities to yield complete control of a phone running the Android platform has been proved possible using the emulator included in the SDK, which emulates phone running the Android platform on an ARM microprocessor.

This advisory contains technical descriptions of these security bugs, including a proof of concept exploit to run arbitrary code, proving the possibility of running code on Android stack (over an ARM architecture) via a binary exploit.


Full advisory here.

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Mar 06, 08 - 10:54 am Comment from: JadisOne

Ouch. Definitely not good news for Google.

Mar 06, 08 - 10:57 am Comment from: Metryq

Needs a catchier headline though, like "Army of Zombie Androids."

Mar 06, 08 - 11:06 am Comment from: Think

And people wonder why Apple is so meticulous about releasing stuff for the iPhone.

Public relations nightmare.

Mar 06, 08 - 11:11 am Comment from: Jim

Isn't this why it's still in BETA??????

Honestly, talk about tin foil hats...

Mar 06, 08 - 11:15 am Comment from: NCMacMan

Don't knock tin foil hats . . . they keep the aliens from reading my thoughts.

Mar 06, 08 - 11:20 am Comment from: CheekyGit

Just another reason why I don't use anything created by Google.

Mar 06, 08 - 11:20 am Comment from: dallas

I agree, This is why companies release Beta editions first. Granted, Google has a long tradition of making things Beta for 2 or more years.

I expect apple to release a Beta of the SDK today and not release the full version until June.

Mar 06, 08 - 11:25 am Comment from: dallas

And Who else here thinks the "Android" name will change when the 1.0 version is released. I don't like it as a name for an operating system. I think they can do better.

Mar 06, 08 - 11:36 am Comment from: R2

Does this post mean that Android is an official competitor of the iPhone? A declaration of war by MDN? Are we gearing up to take it on? Is it going to be the iPhone fanboys and fangirls against the Android squad?

Mar 06, 08 - 11:38 am Comment from: Ampar

"Army of Zombie Androids."

Or Cheney's staff.

Mar 06, 08 - 11:41 am Comment from: Steve516

my hats are lined with gold foil inside a triple layer of aluminum, with a kevlar and nomex lining for heat resistance and all day comfort.

And it has an apple logo on the front.

Mar 06, 08 - 11:46 am Comment from: Bartsimpsonhead

Well, if Google are gonna run Android as a Beta for two-odd years, I guess we can expect Micro$oft to keep Beta-testing Vista for the next several...

Mar 06, 08 - 11:49 am Comment from: Roberto

"...Don't knock tin foil hats . . . they keep the aliens from reading my thoughts..."

...not to mention the CIA, ATF and James Carville..

Mar 06, 08 - 11:52 am Comment from: Ampar

To recap, there's an army of wireless, robotic hats infected with a virus. Don't tell Michael Bay.

Mar 06, 08 - 11:53 am Comment from: slow news day

Where's all the news about Windows Vista viruses? You're slacking MDN.

Mar 06, 08 - 01:39 pm Comment from: Reality Check

So, I hope MDN gives Apple hell next time they release a beta that still has bugs!

Mar 06, 08 - 02:07 pm Comment from: nekogami13

Does google have anything that is not a beta?
I thought that was there M.O., slap something together , release it, claim it is a beta and improve it over the next century.

Mar 06, 08 - 02:55 pm Comment from: montex

This is exactly why I hope Apple keeps an iron fist and lock on the iPhone. We hear so many whiners going on and on about how evil Apple is for bricking hacked iPhones, and how important it is that they be able to run apps on the iPhone, but they only give lip service to security.

I don't want my iPhone hacked by loner malcontents who have nothing better to than to harass people through their technology. Please Apple, keep the iPhone safe. Keep it secure and don't let the nerds worm their way into what is a very good thing!

Mar 06, 08 - 04:20 pm Comment from: qka

Isn't this why it's still in BETA??????

True, but is anything from Google not a Beta?

Mar 06, 08 - 06:17 pm Comment from: Logan

This is the beauty of Open Source. These things will be fixed asap, ensuring security for the time being, until someone else finds a hole. I have a lot of confidence in Google. They are a very interesting counterpart to Apple. One is very open and collaborative, while the other is tight-lipped and meticulous. Both accomplish their goals quite well.

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: