Microsoft Announces Windows 10 BlackBerry Launches Passport in India for Rs. 49,990 The World's Slimmest SmartPhone : Gionee Elife S5.1 iOS 8 Has Finally Arrived Apple Unveils iPhone 6 and iPhone 6 Plus
Posted by : Unknown Thursday, 18 September 2014


Security experts have discovered a new flaw in Android browser that allows attackers to run scripts that can read the contents of any open tab and harvest private data. The security flaw affects Android devices running any version prior to 4.4.

The flaw was first reported by ethical hacker and blogger Rafay Baloch, who has tested it on a variety of devices, since then his findings have further been confirmed by others in the security industry. According to Google's own analytics, this affects at least 75 percent of all Android users as very large proportion of new phones also ship with Android 4.3 or lower.

According to reports the problem relates the Single-Origin Policy, which can be bypassed for the Android browser by deliberately feeding it a malformed instruction which allows scripts to be run without supervision. This simple exploit allows attackers to read data even from secure sites once they are opened, and redirect the data to any external site.

According to Baloch, "A SOP bypass occurs when a siteA.com is some how able to access the properties of siteB.com such as cookies, location, response etc. Due to the nature of the issue and potential impact, browsers have very strict model pertaining it and a SOP bypass is rarely found in modern browsers, however, they are found once in a while."
Security experts have discovered a new flaw in Android browser that allows attackers to run scripts that can read the contents of any open tab and harvest private data. The security flaw affects Android devices running any version prior to 4.4.
The flaw was first reported by ethical hacker and blogger Rafay Baloch, who has tested it on a variety of devices, since then his findings have further been confirmed by others in the security industry. According to Google's own analytics, this affects at least 75 percent of all Android users as very large proportion of new phones also ship with Android 4.3 or lower.
- See more at: http://www.digit.in/mobile-phones/android-security-flaw-affects-millions-of-users-23921.html#sthash.Nu0pgKIr.dpuf

Leave a Reply

Subscribe to Posts | Subscribe to Comments

Categories

Designed by Cyber Freak

News Flash


Blog Archive

Powered by Blogger.

Copyright © Cyber Era News. All rights reserved.- Powered by Eravations - Designed by Shantanu Chauhan -