Android 4.3 Jelly Bean and v4.4 KitKat affected by critical VPN flaw: CERT-In

Advertisement
By Press Trust of India | Updated: 3 March 2014 18:35 IST
A "critical flaw" has been detected by the Computer Emergency Response Team of India (CERT-In) in the virtual private network (VPN) offered by Android operating systems in Indian cyberspace, leading to a "hijack" of the personal data of users.

Indian Internet security sleuths have alerted consumers of the vulnerability to the Web-based service which affects computer systems and mobile phones using the Android system.

The suspicious activity has been noticed by CERT-In in two Android versions - v4.3 known as 'Jelly Bean' and the latest v4.4 called 'Kit Kat'.

Advertisement

"A critical flaw has been reported in Android's (virtual private network) VPN implementation, affecting Android version 4.3 and 4.4 which could allow an attacker to bypass active VPN configuration to redirect secure VPN communications to a third party server or disclose or hijack unencrypted communications," CERT-In said in a latest advisory to users of this network.

CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of the Indian Internet domain.

Advertisement

VPN technology is used to create an encrypted tunnel into a private network over public Internet. Organisations and groups of people use such connections to enable employees or acquaintances to securely connect to enterprise networks from remote locations through multiple devices, from laptops to desktops to mobiles and tablets.

The agency said the current malicious application is capable of diverting the VPN traffic "to a different network address" and successful exploitation of this issue "could allow attackers to capture entire communication originating from affected device."

Advertisement

"It is noted that not all applications are encrypting their network communication. Still there is a possibility that attacker could possibly capture sensitive information from the affected device in plain text like email addresses, IMEI number, SMSes, installed applications," the advisory said.

Cyber-experts said that this anomaly could only lead to capture and viewing the data which is in plain text and Android applications directly connecting to the server using SSL will not be affected.

Advertisement

Websites which use 'https' in their URL will also be safe.

The cyber-agency has also suggested some countermeasures to beat this threat.

"Apply appropriate updates from the original equipment manufacturer, do not download and install applications from untrusted sources, maintain updated mobile security solution or mobile anti-virus solutions on the device, exercise caution while visiting trusted or untrusted URLs and do not click on the URLs received via SMS or email unexpectedly from trusted sources, or received from untrusted users" are some of the combat techniques which have been suggested by the agency.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  3. Redmi A7 Pro 4G and Redmi A7 4G Launched in India With These Features
  4. Samsung Galaxy A57, A37 Review: Is Samsung's 'A-Game' Worth the Price?
  5. Motorola Edge 70 Fusion Review
  6. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  7. iPhone 18 May Not Arrive With Hardware Upgrades as Apple Cuts Costs: Report
  8. These Vivo Smartphones Will Cost More in India Due to the Latest Price Hike
  9. Redmi Buds 8 Launched With Up to 50dB ANC, Up to 44 Hours Total Battery Life
  10. Assassin's Creed Black Flag Resynced Will Be Revealed This Week
  1. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  2. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  3. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  4. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  5. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  6. Deezer Claims 75,000 AI-Generated Songs Are Being Uploaded to the Platform Daily
  7. Heartbeat Season 2 OTT Release Date: Know When and Where to Stream This Medical Drama Online
  8. Vivo Y600 Pro Listings on Geekbench, Regulatory Databases Reveal Key Specifications, Features
  9. Redmi Buds 8 Launched With Up to 50dB ANC, Up to 44 Hours Total Battery Life: Price, Features
  10. Coinbase Rolls Out Crypto-Backed Loans in the UK as FCA Shapes Rules
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.