Android 4.1.1 devices vulnerable to Heartbleed bug, says Google

Advertisement
By NDTV Correspondent | Updated: 14 April 2014 12:14 IST
Google has joined the ranks of companies which have issued public warnings about their products being vulnerable to exploitation thanks to the massively widespread Heartbleed bug. The company has now disclosed that users of all Android versions except specifically 4.1.1 are unaffected.

Buried at the bottom of a blog post titled Google Services Updated to Address OpenSSL CVE-2014-0160 (the Heartbleed bug), the search and online services giant added that 'patching information' for Android 4.1.1 is being distributed to device manufacturers and carriers, who are responsible for creating and issuing updates.

Android version fragmentation is a known problem within the ecosystem, and millions of users could still be running version 4.1.1, also known by the codename Jelly Bean. According to Google's own Android developer dashboard, up to 34.4 percent of all Android users are currently running 4.1 - 4.1.2, though the exact number or percentage of users running 4.1.1 is not known.

Advertisement

Version 4.1.1 was a minor update to 4.1 containing bug fixes related to specific devices. Version 4.1.2 was released less than three months later, potentially limiting the scope of the number of devices affected. However, Android manufacturers are frequently criticised for shipping devices built with older Android builds, and not issuing updates thereafter. A large number of budget devices are never updated once they are shipped.

Google has further disclosed that its Web services Search, Gmail, YouTube, Wallet, Play, Apps, App Engine, AdWords, DoubleClick, Maps, Maps Engine and Earth were affected by Heartbleed but have now been patched. Other vulnerable websites included Dropbox, Facebook, Twitter, Tumblr, Yahoo, GoDaddy, and Amazon Web Services.

Advertisement

By contrast, Apple has stated that iOS, OS X, and its widely used Web services including iTunes and iCloud were never affected.

Heartbleed is a bug in the OpenSSL encryption framework used by Web servers to secure communications between themselves and the outside world. In early April, it was reported that attackers were able to retrieve information including sensitive encryption keys, user account details and message contents, from servers running the vulnerable version of OpenSSL.

Advertisement

Security workers have since demonstrated hacks that have resulted in retrieval of working encryption keys. It is not knows whether attackers, including government-sponsored agencies, were aware of the existence of the Heartbleed bug and were exploiting it before it became widely known.


 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. This Realme Smartphone Could Launch in India With an 8,000mAh Battery
  2. WhatsApp Could Soon Offer Messenger-Like Chat Bubbles on Android
  1. Kaadhal Enbadhu Podhuudamai Out on OTT: Where to Watch it Online?
  2. The Legend of Vox Machina Season 4 OTT Release Date: When and Where to Watch it Online?
  3. Aadu 3 OTT Release Date Revealed: Know When and Where to Stream it Online
  4. Safe House (2025) Now Streaming Online: Cast, Plot, Trailer and Where to Watch
  5. Uranus’ Outer Rings May Reveal Hidden Moons, Scientists Say
  6. WhatsApp Is Finally Working on Adding Support for Android's Notification Bubbles Feature
  7. Realme C100x Tipped to Launch in India Soon as Key Specifications and Design Surface Online
  8. Morgan Stanley Announces MSILF Stablecoin Reserves Portfolio for Issuers
  9. Jio Youth and Gaming Plan With Snapchat+, FanCode and Gemini Pro Launched: Price, Benefits
  10. Infinix GT 50 Pro Launched With Dimensity 8400 Ultimate, HydroFlow Liquid Cooling, Shoulder Triggers: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.