Breaking News

Razer Unveils the Ultra-Lightweight DeathAdder V4 Pro Sony launches a high-resolution shotgun microphone with superior sound quality and compact design. Arctic announces New Liquid Freezer III Pro 280 and Pro 420 Silicon Power Launches Hypera microSDXC Express Card Samsung announces Watch8, Z Fold7 and Z Flip7

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Comments On Lack Of Security Patches On Older Android Phones

Google Comments On Lack Of Security Patches On Older Android Phones

Smartphones Jan 25,2015 0

Google says that although there is a web security flaw in your older Android phone, it has some good reasons for holding off a security update. Sicne last week there have been numerous public discussion related to vulnerabilities in versions of Webkit - a framework that lets apps show websites without a separate browser) - with people asking questions about security of browsers and WebView on Android 4.3 (Jellybean) and earlier.

As the company's Adrian Ludwig explains, it's no longer viable to "safely" patch vulnerable, pre-Android 4.4 versions of WebView to prevent remote attacks. The amount of necessary code changes would create new problems, he claims, especially since developers are introducing "thousands" of tweaks to the open source software every month.

He also suggested steps users and developers can take to mitigate the risk of potential exploitation of WebKit vulnerabilities without updating to Lollipop.

"Using a browser that is updated through Google Play and using applications that follow security best practices by only loading content from trusted sources into WebView will help protect users," Ludwig says.

When browsing on any platform, users should make sure to use a browser that provides its own content renderer and is regularly updated. For instance on Android, Chrome or Firefox are both options since they are securely updated through Google Play often: Chrome is supported on Android 4.0 and greater, Firefox supports Android 2.3 and greater. Chrome has been the default browser for all Nexus and Google Play edition devices since 2012 and is pre-installed on many other popular devices (including Galaxy devices from Samsung, the G series from LG, the HTC One series, and the Motorola X and G).

Application developers should make sure that they are following all security best practices [http://goo.gl/b6a3ta]. In particular, to resolve this issue when using WebView [http://goo.gl/FKeouw], developers should confirm that only trusted content (e.g. loaded from a local source or over HTTPS) is displayed within WebViews in their application. For maximum security when rendering content from the open web, developers should consider providing their own renderer on Android 4.3 and earlier so that they can keep it up to date with the latest security patches.

Tags: android
Previous Post
NVIDIA Comments On GeForce GTX 970 Memory Allocation Reports
Next Post
Sony is Offering Old Games To Settle The 2011 PlayStation Network Breach

Related Posts

  • What’s new in Android 15, plus more updates

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • Android Gets a New Keyboard for Typing Braille

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

Latest News

Razer Unveils the Ultra-Lightweight DeathAdder V4 Pro
PC components

Razer Unveils the Ultra-Lightweight DeathAdder V4 Pro

Sony launches a high-resolution shotgun microphone with superior sound quality and compact design.
Cameras

Sony launches a high-resolution shotgun microphone with superior sound quality and compact design.

Arctic announces New Liquid Freezer III Pro 280 and Pro 420
Cooling Systems

Arctic announces New Liquid Freezer III Pro 280 and Pro 420

Silicon Power Launches Hypera microSDXC Express Card
Cameras

Silicon Power Launches Hypera microSDXC Express Card

Samsung announces Watch8, Z Fold7 and Z Flip7
Smartphones

Samsung announces Watch8, Z Fold7 and Z Flip7

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Pure Base 501

be quiet! Pure Base 501

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed