Register now » Login
« Login

Forgotten your password?

OsmAnd

Jan

31

Researcher Exposes MicroSD Security Vulnerability In Android 2.3

by Douglas Carter on Jan 31, 2011 8:41:14 PM — read 1,364 times

Xuxian Jiang, a computer security researcher at North Carolina State University discovered a security issue with Android 2.3 while conducting "an Android-related research project" which allows an attacker to access information stored on the unlucky user's microSD card, including photos, personal and financial information, voicemails, and videos.

According to the source, the attack can occur by just selecting a link on a malicious site and can also find out what apps are installed on the phone.

Perhaps even more alarming is that the nature of the vulnerability is apparently not new. Last year, a similar exploit was uncovered for Android 2.2, which Google fixed. However, Jiang was able to bypass the fix used in Gingerbread.

Google told eWeek that Mr. Jiang has already contacted them about the vulnerability and that a fix is being made, which should be released in the next official update. In the mean time, there are ways for Gingerbread users to protect themselves.

Jiang explains that to protect themselves from the exploit, users can unmount the sdcard (not recommend), disable javascript, or use "a third-party browser for the time being." Finally, just be careful about what sites you choose to visit.

I'll personally be taking no steps against this vulnerability other than being a little more careful about which sites I visit. However, that doesn't mean that others users shouldn't be concerned, as I have uncovered no evidence whether or not the vulnerability is already being exploited for malicious intent.

If anyone asks you whether there are security risks within Android, don't hesitate to use this case as an example.

Image from Engadget

Comments

Feb 1, 2011 7:10:47 AM

There's security risks for all os's. Even apple's os has vulnerabilities, it's when an os has a large share of the market that people make malicious software to attack it.

Feb 1, 2011 10:05:58 PM

Exactly. The people making the malicious software will want the biggest bang for their buck, so they'll target the most used OSes. I'm surprised that I don't hear more about vulnerabilities in iOS devices though. You'd think with their popularity, they' be attracting their own amount of malware. The microSD card function obviously isn't there, but they could be targeted in other ways...

Write new comment:

You must log in or register now,
to submit a comment!

As a logged in user, you can also change the order of the comments.

 
Ad

Bookmark / E-Mail

Click on an icon to bookmark this article.
» Send this article via e-mail

Tags / Topics

Archive

Android Forum

General
Android
Google Android Phones
HTC Android Phones
Huawei Android Phones
LG Android Phones
Motorola Android Phones
Samsung Android Phones
Sony Ericsson Android Phones
Other Android Devices
Android Tablets
Other Android Tablets
Android OS Forums
Android Developer Forum
Miscellaneous

Support AndroidPIT

Do you enjoy AndroidPIT? We?re thrilled to have your support! How does it work? Just click on the links below.

Recommend to Others

Enjoy AndroidPIT? Then please let other people know about us!

Questions / Help

Do you have questions about AndroidPIT or simply want to learn more about us? Then you might find the following links helpful.

  You are reading: Researcher Exposes MicroSD Security Vulnerability In Android 2.3 - AndroidPIT. All times are UTC+02:00. The time now is 5:16 PM.