Falla disclosed for the G1, the first Smartphone with Android

Charles A. Miller, who reportedly managed to violate the security of a Mac in just 2 minutes during the CanSecWest, who is now in charge of the first reported vulnerability in Android, which affects the Smartphone G1, launched jointly by Google and T-Mobile.

The flaw could be exploited by visiting a website created for this purpose, and would take control of the events that happen within that space (the web browser).

According to the people of Google, the system is designed so that each application run in a “sandbox” (sandbox in English, which would be a ‘limited’), so as not to affect other parts of the cellphone.

Still, if the flaw affects the web browser and this can take control over the navigation of the user, could store quietly implies that key sites and web applications, as they operate within the same sandbox.

Since Google is not quite agree with the ways of Miller, since they ensure that this error has been reported in public, without first giving the company time to fix the problem.

Miller replied that only has to know the problem, although it has not yet revealed details, and did so simply because it believes that consumers have a right to know of such issues.

Vale stressed that the flaw has been corrected in a new version of Android, although this is not present in the mobile already sold, so Google is working with T-Mobile to enable its customers install the updates.

Posted on December 2, 2008


Comments

Leave a Comment

If you would like to make a comment, please fill out the form below.

Name (required)

Email (required)

Website

Comments