
While some of the Android vulnerabilities we have been hearing about lately were easily avoided, some are decidedly more menacing because they are easier to fall prey to. Today's reported Android security breach falls squarely in that last category. There is a new exploit that can compromise any Android smartphone through Chrome, just from visiting certain websites. This exploit allows an attacker to gain full control of the device. Here's a quote with more of the details,
The attack was demonstrated earlier this week at the PacSec conference in Japan, where Quihoo 360 researcher Guang Gong demonstrated the attack against Google’s mobile Chrome browser. A vulnerability in the app’s JavaScript V8 engine allows attackers to do largely whatever they’d like to a victim’s phone – the demo showed how apps could be silently installed, but that’s just one way a hacker might seek to take advantage of the bug.
With Chrome so pervasive on Android phones and tablets, this means that a huge percentage of the current Android user base is potentially exposed. ~ PocketNow
There is some bright news regarding this vulnerability. It looks like researchers may have found it so fast that the bad guys haven't even had a chance to develop and use it.
That's one of the best things about Android. It's community of developers rally together to constantly test the boundaries and limits of the technology. It's because of them that we frequently get fixes for problems before they ever become a problem. The word on the street is that a fix for this is in the works and should be coming soon.