Commentary
Android SDK Not Secure, Vulnerable To Attack
According to researchers, certain open-source image processing libraries in Google's Android SDK are outdated and can be attacked by hackers. A total of eight vulnerabilities were found by Core Security. Core showed that the weaknesses can result in hackers taking complete control of Android handsets.According to researchers, certain open-source image processing libraries in Google's Android SDK are outdated and can be attacked by hackers. A total of eight vulnerabilities were found by Core Security. Core showed that the weaknesses can result in hackers taking complete control of Android handsets.Core issued an advisory yesterday, and said, "Several vulnerabilities have been found in Android's core libraries for processing graphic content in some of the most used image formats (PNG, GIF an BMP). While some of these vulnerabilities stem from the use of outdated and vulnerable open-source image processing libraries, others were introduced by native Android code that use them or that implements new functionality."
Losing total control to hackers is a worst-case scenario. But I don't think there's any cause for alarm.
More Internet Insights
White Papers
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
Reports
- How Google+, Facebook Impact Corporate Strategy: Social Media and IT at a Crossroads
- Strategy: Enterprise Social Network Buyer's Guide
Webcasts
- Maximize ROI with Database Consolidation onto Private Clouds
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
Keep in mind that the Android platform is currently available to developers in a beta release. Even though some hardware vendors have shown off working prototypes using early versions of the code, the final version of Android won't be available until later this year. Neither will handsets. The development community will likely find more weaknesses and bugs in Android before the final build is created.
According to the official Android Developers Blog, Google was aware of the problem, and issued a fix in the latest build of the platform (which was released last month).
Reports like this are going to continue to bubble to the surface as developers dig their fingers into the code. Creating a mobile platform takes time. Finding and fixing bugs is part of the process. The final version of Android will have all the ingenuity and skills of the Linux developer community behind it. That is sure to include rock-solid security.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- Red Alert: Why Tablet Security Matters - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Resource
Download this whitepaper and find out how to easily manage web content by categorizing it into a discrete number of categories.
Learn More












