This past week, mobile security start up firm BlueBox Security announced that it had found a serious vulnerability in Google’s Android mobile operating system (the software underlying most of the world’s smartphones and tablets), which it dubbed a ‘master key’ (a fairly accurate description). Using this flaw, an attacker can completely take over an Android mobile device, unbeknownst to its owner. This includes listening in on any conversations either on or near the device, stealing any data stored on it and co-opting the device into a mobile botnet to send spam messages to others. Moreover, the flaw can be found in every version of the OS stretching back to 2009’s version 1.6 (known as ‘Donut’) and affects 99% of all Android devices. Yes, this is a serious problem and the story was soon picked up in mainstream news sources like the BBC and NBC News.
BlueBox had intended the announcement as a ‘teaser,’ with details on the flaw to be offered at a security conference on August 1st, but hackers figured it out within five days. As a result, this is not a theoretical threat.
Read more ›



