Skip to main content

Google rolls out security fix for Android data leak flaw

Google Android LogoA report surfaced earlier this week indicating that there’s a security risk affecting 99 percent of Android devices. That’s a pretty large number, and Google unsurprisingly responded swiftly, bringing the hammer down on the Android OS with a shiny, new fix.

News of the potential security issue came from research conducted at Germany’s University of Ulm. The flaw affects all versions of Android version 2.3.3 or older and stems from the authentication protocol ClientLogin. Basically, your average app communicates with Google to request an “authentication token” (authToken) by sending over the device user’s account name and password via a secure connection. The authToken lives for no more than 14 days, but it can be reused during that time and there’s a danger of it being captured by an “adversary,” who would then be able to extract any personal data exchanged by the app. Follow the source link for a much more knowledgeable (and technical) explanation, but that’s the basic gist of it.

Not the cataclysmic security flaw that the “99 percent of all devices are affected” statistic might suggest, but worrisome enough. Especially in this particular moment, when many of us are acutely aware of private data security concerns following Sony’s recent troubles. The security update from Google has already started to roll out, as the company revealed in a statement to Digital Trends:

“Today we’re starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts. This fix requires no action from users and will roll out globally over the next few days.”

Editors' Recommendations

Adam Rosenberg
Former Digital Trends Contributor
Previously, Adam worked in the games press as a freelance writer and critic for a range of outlets, including Digital Trends…
How to get Android apps on a Chromebook
Dell Chromebook 3189 2-in-1 on a classroom desk floating in the air.

Over the last few years, Android apps have been added to more and more Chromebook models. A brilliant expansion of the overall user experience, Google went ahead and integrated the Play Store into most Chromebooks made after 2019. This is the most convenient way to download an Android app or two, but if you own an older Chromebook, the machine may not have native support for downloading and installing applets.

To confirm this, we recommend referencing this extensive Android app support list from The Chromium Projects.

Read more
Android 15 release date: When will my phone get the update?
The Android 15 logo on a smartphone.

Google has announced Android 15, the next major evolution of its mobile operating system. As usual, the development and release cycle will follow a three-phase strategy. February 16, 2024, marked the start of the first phase, which squarely targets developers and phone makers to provide them with a look at the changes so that they can get familiar with the new software.

The first build of Android 15 is the Developer Preview phase, and a Beta release follows it. This release can be downloaded over the air without any special tactics. Once the beta testing phase is over, the final stable version is released. This usually happens toward the end of the year.
All the phones that can download Android 15

Read more
The 6 biggest announcements we expect from Google I/O 2024
Google I/O 2019

Google will hold its annual developer conference, Google I/O 2024, on May 14 in Mountain View, California. The event is about a month away, and we're expecting a few big announcements.

As with any Google I/O event, this year's conference will start with a big opening keynote presentation from CEO Sundar Pichai. But what actual announcements are we looking forward to? Here are a few of the biggest things that we are likely to see at Google I/O 2024.
Android 15

Read more