News

Google Issues Mobile OS Security Fix

Google Inc. has rolled out a security patch for a flaw found last week in its Android operating system for mobile devices.

The over-the-air-patch appears as an update in T-Mobile's G1 phone and in other devices that can run the Linux-based OS. The phones prompt the user to accept the update "now" or "later" but a restart is needed for the patch to take effect.

Last week, security pros at Baltimore-based Independent Security Evaluators described the problem, explaining that users of Android-enabled phones could be exposed to hacks when routed to a malicious Web page. Upon visiting the malicious site, the attacker can run any code they wish based on the privileges of a Web browser application.

Depending on how a mobile handset was configured, an attacker could have access to elements such as cookies and saved passwords but would not be able to access other functions, Independent Security Evaluators said.

The flaw remains limited because of Android's open source architecture. Given the nature of real-time development in the open source community, it can be difficult to roll out a product but relatively easy to fix holes. Developers have ready access to the source code, which is constantly being enhanced.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Featured

  • SameSite Cookie Changes Rolled Back Until Summer

    The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

  • Basic Authentication Extended to 2H 2021 for Exchange Online Users

    Microsoft is now planning to disable Basic Authentication use with its Exchange Online service sometime in the "second half of 2021," according to a Friday announcement.

  • Microsoft Offers Endpoint Configuration Manager Advice for Keeping Remote Clients Patched

    Microsoft this week offered advice for organizations using Microsoft Endpoint Configuration Manager with remote Windows systems that need to get patched, and it also announced Update 2002.

  • Azure Edge Zones Hit Preview

    Azure Edge Zones, a new edge computing technology from Microsoft designed to enable new scenarios for developers and partners, emerged as a preview release this week.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.