IntoMobile

Breaking news, information, and analysis on the latest mobile phones and mobile technology

Open NavigationOpen Search
  • Home
  • Platforms
    • iOS / iPhone OS
    • Android
    • Windows Phone
    • BlackBerry OS
  • Hardware
    • New Hardware
    • Tablets
    • Reviews
    • Rumors
  • Carriers
    • AT&T
    • Sprint
    • T-Mobile
    • Verizon
  • Manufacturers
    • Apple
    • Samsung
    • HTC
    • LG
    • Motorola
  • Best VPNs
    • Best VPNs for iPhone
    • Best VPNs for Android

Android 2.3 Gingerbread security flaw reveals microSD contents to attackers

January 29, 2011 by Kelly Hodgkins - 6 Comments

Android Froyo and Gingerbread
Share on Twitter Share on Facebook ( 0 shares )

Android Froyo and Gingerbread

Xuxian Jiang, a computer security researcher at the North Carolina State University, has identified a security flaw in Android 2.3 Gingerbread. The vulnerability provides access to the microSD card and applications directory on Android 2.3 handsets By clicking on a link, malicious code on a website could access the data on a microSD card including voicemail, photos, and other saved data. Once scanned, these files can be uploaded to a remote server. In a similar manner, the vulnerability also lets attackers scan and upload the installed and built-in applications on a handset. The vulnerability was discovered as part of a research project and was confirmed using a Nexus S running Android 2.3 Gingerbread.

To avoid being compromised by this exploit in wild, Gingerbread users can remove or disable their microSD card, but this preventive measure may prohibit you from saving photos or voicemails to your phone. You can also disable JavaScript in the built-in Android browser, but you may not be able to view certain websites that require JavaScript to function properly. The last and perhaps the least disruptive preventive measure, is to switch to a third-party browser like Firefox.

Google has recently fixed a troubling SMS bug that led to SMS messages being sent to the wrong contact. A fix was put in place that corrected the SMS issue but, according to Jiang, this can be easily bypassed. eWeek has examined this issue and confirmed that Google is working on a solution to block this hole. As of the writing of this post, there is no official confirmation from Google on when this vulnerability will be fixed.

[Via North Carolina State, Engadget, eWeek]

Share on Twitter Share on Facebook ( 0 shares )

Back to top ▴

Back to top ▴

Follow IntoMobile

38k
36k
4k
13k
12k

Most Recent Posts

  • iPhone No Sound: Tips on How to Fix this Common Issue
  • The newest iOS – things you surely did not know
  • Transferring money through mobile: Why digital wallets are the future of commerce?
  • Review: Shine laser light Bluetooth headphones
  • Neptune Suite smart watch with phone and tablet screens killing it at Indiegogo

Get Updates Via E-Mail

  • This field is for validation purposes and should be left unchanged.

About IntoMobile

  • About IntoMobile
  • Contact IntoMobile
  • Send us News Tips
  • Privacy Policy

Social Links

  • IntoMobile on Facebook
  • IntoMobile on Twitter
  • IntoMobile on Google+
  • IntoMobile on YouTube

Copyright © 2006-2021 IntoMobile. All rights reserved.