Skip to main content

Google rolls out security fix for Android data leak flaw

Google Android LogoA report surfaced earlier this week indicating that there’s a security risk affecting 99 percent of Android devices. That’s a pretty large number, and Google unsurprisingly responded swiftly, bringing the hammer down on the Android OS with a shiny, new fix.

News of the potential security issue came from research conducted at Germany’s University of Ulm. The flaw affects all versions of Android version 2.3.3 or older and stems from the authentication protocol ClientLogin. Basically, your average app communicates with Google to request an “authentication token” (authToken) by sending over the device user’s account name and password via a secure connection. The authToken lives for no more than 14 days, but it can be reused during that time and there’s a danger of it being captured by an “adversary,” who would then be able to extract any personal data exchanged by the app. Follow the source link for a much more knowledgeable (and technical) explanation, but that’s the basic gist of it.

Not the cataclysmic security flaw that the “99 percent of all devices are affected” statistic might suggest, but worrisome enough. Especially in this particular moment, when many of us are acutely aware of private data security concerns following Sony’s recent troubles. The security update from Google has already started to roll out, as the company revealed in a statement to Digital Trends:

“Today we’re starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts. This fix requires no action from users and will roll out globally over the next few days.”

Editors' Recommendations

Adam Rosenberg
Former Digital Trends Contributor
Previously, Adam worked in the games press as a freelance writer and critic for a range of outlets, including Digital Trends…
How to download the Android 15 beta right now
The Android 15 logo on a smartphone.

Android 15, Google's next major Android update, is now available for testing. Following a couple of developer previews launched earlier this year, Google released the first Android 15 beta on April 11 — making it available for anyone to try.

Read more
Google just released the first Android 15 beta. Here’s what’s new
The Android 15 logo on a smartphone.

Google has just released the first public beta build of Android 15, marking an end to the developer-focused test phase. The beta version’s release also means that Android 15 is finally in a state where it can be tried by the masses without people having to worry about too many bugs leaving their phone in a sorry state.

The first beta version of Android 15 doesn’t introduce a ton of new features, as most of the notable additions have already appeared in the Developer Preview builds. Google’s blog post, however, mentions the following features as the key highlights

Read more
The Google Pixel 8a leaked again, and now I’m nervous
Pixel 7a back.

Just about everything regarding the Google Pixel 8a has leaked at this point. We've seen high-quality renders of the phone, its specs are everywhere online, and its release date is all but guaranteed. A new Pixel 8a leak appeared online today, and after seeing it, I'm feeling a bit nervous.

TechDroider on X (formerly Twitter) shared two hands-on photos of the Pixel 8a today, including pictures of the front and back of the phone. The back of the phone showcases a black color with a matte finish that looks quite good. We also get a clear view of the two rear cameras, the Google "G" logo in the middle, and the rounded corners.

Read more