Skip to main content

Google rolls out security fix for Android data leak flaw

Google Android LogoA report surfaced earlier this week indicating that there’s a security risk affecting 99 percent of Android devices. That’s a pretty large number, and Google unsurprisingly responded swiftly, bringing the hammer down on the Android OS with a shiny, new fix.

News of the potential security issue came from research conducted at Germany’s University of Ulm. The flaw affects all versions of Android version 2.3.3 or older and stems from the authentication protocol ClientLogin. Basically, your average app communicates with Google to request an “authentication token” (authToken) by sending over the device user’s account name and password via a secure connection. The authToken lives for no more than 14 days, but it can be reused during that time and there’s a danger of it being captured by an “adversary,” who would then be able to extract any personal data exchanged by the app. Follow the source link for a much more knowledgeable (and technical) explanation, but that’s the basic gist of it.

Not the cataclysmic security flaw that the “99 percent of all devices are affected” statistic might suggest, but worrisome enough. Especially in this particular moment, when many of us are acutely aware of private data security concerns following Sony’s recent troubles. The security update from Google has already started to roll out, as the company revealed in a statement to Digital Trends:

“Today we’re starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts. This fix requires no action from users and will roll out globally over the next few days.”

Editors' Recommendations

Adam Rosenberg
Former Digital Trends Contributor
Previously, Adam worked in the games press as a freelance writer and critic for a range of outlets, including Digital Trends…
The Google Pixel 8a leaked again, and now I’m nervous
Pixel 7a back.

Just about everything regarding the Google Pixel 8a has leaked at this point. We've seen high-quality renders of the phone, its specs are everywhere online, and its release date is all but guaranteed. A new Pixel 8a leak appeared online today, and after seeing it, I'm feeling a bit nervous.

TechDroider on X (formerly Twitter) shared two hands-on photos of the Pixel 8a today, including pictures of the front and back of the phone. The back of the phone showcases a black color with a matte finish that looks quite good. We also get a clear view of the two rear cameras, the Google "G" logo in the middle, and the rounded corners.

Read more
Android phones finally have their own version of AirTags
Renders of Chipolo's new Point trackers that work with Google's Find My Device network.

Google's new Find My Device tracking service will soon launch with an important third-party provider. Chipolo has announced two new trackers for the service: the Chipolo One Point item tracker and the Chipolo Card Point wallet finder.

By offering these trackers, Chipolo will be among the first companies in the market to provide trackers that work with Google's new tracking network. Google announced its new Find My Device network last year. In short, it's Google's answer to Apple's Find My network. Find My Device can use other nearby Android devices to track your lost phone, item tracker, etc. — just like how Find My uses iPhones and other Apple devices to locate lost iPhones and AirTags.

Read more
This Google Pixel 8a leak just spoiled everything about the phone
A person holding the Google Pixel 8, showing the back of the phone.

Previous leaked render of the Google Pixel 8a. Smart Prix

We are, in theory, only just over a month away from an official unveiling of Google's newest midrange smartphone, the Google Pixel 8a. However, it seems you won't have to wait until Google I/O 2024 to find out what Google has planned, as a leaker has just revealed everything we need to know about the latest entry in the Pixel roster.

Read more