Breaking News

DJI Breaks Through the Limits of Fixed Aperture with Osmo Action 6 PlayStation’s Black Friday Deals 2025 TerraMaster Black Friday & Cyber Monday 2025 Mega Sale Is Here HighPoint and ASK Corp Redefine 8K Post-Production with Verified 50.5GB/s Gen5 NVMe Storage at Inter BEE 2025 EDIFICE Launches the New ECB-S10 Series

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Comments On Lack Of Security Patches On Older Android Phones

Google Comments On Lack Of Security Patches On Older Android Phones

Smartphones Jan 25,2015 0

Google says that although there is a web security flaw in your older Android phone, it has some good reasons for holding off a security update. Sicne last week there have been numerous public discussion related to vulnerabilities in versions of Webkit - a framework that lets apps show websites without a separate browser) - with people asking questions about security of browsers and WebView on Android 4.3 (Jellybean) and earlier.

As the company's Adrian Ludwig explains, it's no longer viable to "safely" patch vulnerable, pre-Android 4.4 versions of WebView to prevent remote attacks. The amount of necessary code changes would create new problems, he claims, especially since developers are introducing "thousands" of tweaks to the open source software every month.

He also suggested steps users and developers can take to mitigate the risk of potential exploitation of WebKit vulnerabilities without updating to Lollipop.

"Using a browser that is updated through Google Play and using applications that follow security best practices by only loading content from trusted sources into WebView will help protect users," Ludwig says.

When browsing on any platform, users should make sure to use a browser that provides its own content renderer and is regularly updated. For instance on Android, Chrome or Firefox are both options since they are securely updated through Google Play often: Chrome is supported on Android 4.0 and greater, Firefox supports Android 2.3 and greater. Chrome has been the default browser for all Nexus and Google Play edition devices since 2012 and is pre-installed on many other popular devices (including Galaxy devices from Samsung, the G series from LG, the HTC One series, and the Motorola X and G).

Application developers should make sure that they are following all security best practices [http://goo.gl/b6a3ta]. In particular, to resolve this issue when using WebView [http://goo.gl/FKeouw], developers should confirm that only trusted content (e.g. loaded from a local source or over HTTPS) is displayed within WebViews in their application. For maximum security when rendering content from the open web, developers should consider providing their own renderer on Android 4.3 and earlier so that they can keep it up to date with the latest security patches.

Tags: android
Previous Post
NVIDIA Comments On GeForce GTX 970 Memory Allocation Reports
Next Post
Sony is Offering Old Games To Settle The 2011 PlayStation Network Breach

Related Posts

  • What’s new in Android 15, plus more updates

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • Android Gets a New Keyboard for Typing Braille

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

Latest News

DJI Breaks Through the Limits of Fixed Aperture with Osmo Action 6
Cameras

DJI Breaks Through the Limits of Fixed Aperture with Osmo Action 6

PlayStation’s Black Friday Deals 2025
Gaming

PlayStation’s Black Friday Deals 2025

TerraMaster Black Friday & Cyber Monday 2025 Mega Sale Is Here
Enterprise & IT

TerraMaster Black Friday & Cyber Monday 2025 Mega Sale Is Here

HighPoint and ASK Corp Redefine 8K Post-Production with Verified 50.5GB/s Gen5 NVMe Storage at Inter BEE 2025
Enterprise & IT

HighPoint and ASK Corp Redefine 8K Post-Production with Verified 50.5GB/s Gen5 NVMe Storage at Inter BEE 2025

EDIFICE Launches the New ECB-S10 Series
Consumer Electronics

EDIFICE Launches the New ECB-S10 Series

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed