Android Browser Security Hole Affects Millions of Users, Says Expert

Advertisement
By NDTV Correspondent | Updated: 16 September 2014 12:12 IST
A massive security vulnerability has been discovered in all versions of the default Android browser, which is in use on millions of devices around the world. The flaw allows attackers to run scripts that can read the contents of any open tab, including things such as cookies and credentials that might let them harvest private data even later.

Users of devices running any version of Android prior to 4.4 with the standard browser are affected. According to Google's own analytics, quoted by Android Central and security community website SecurityStreet, this affects at least 75 percent of all Android users. A very large proportion of new phones also ship with Android 4.3 or lower.

The flaw was first publicised by ethical hacker and blogger Rafay Baloch, who has since tested it on a variety of devices. His findings have further been confirmed by others in the security industry. A module that exploits this flaw is also now widely available for the Metasploit penetration testing framework.

The problem relates to the inability of the Android (AOSP) browser to uphold a fundamental assumption, which is that websites which are open should be able to execute scripts, but those should not be able to affect the contents of any other open websites. The concept, known as Single-Origin Policy, can be bypassed for the Android browser by deliberately feeding it a malformed instruction which allows scripts to be run without supervision. The relatively simple exploit thus allows attackers to read data even from secure sites once they are opened, and redirect the data to wherever they want.

Google has not yet responded to the disclosure. The Android browser was officially deprecated in favour of Chrome with Android 4.4. A huge number of devices currently in use will never be updated to 4.4, including many low-priced ones that are being sold as new today.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. DoT's SIM Binding Rule Explained: How Messaging Apps Will Verify Users
  2. Realme C83 5G Debuts in India With a 7,000mAh Battery at This Price
  3. Google Pixel 10a Review: More of the Same?
  4. OTT Releases This Week: Gandhi Talks, Subedaar, War Machine, Hello Bachhon, and More
  5. Here's When the Poco C85x 5G Will be Launched in India
  6. The Upcoming Poco X8 Pro Series Could be Launched Globally on This Date
  7. iPhone 17e vs OnePlus 15R vs iQOO 15R: Price in India, Features Compared
  1. Vivo X300 Max With Zeiss Cameras and Android 16 Spotted at MWC 2026, Could Launch Soon
  2. WhatsApp Update Introduces Support for Discovering Stickers While Typing Emoji: How It Works
  3. This AI-Powered Portable Device Claims to Detect Microphones and Jam Audio Recordings
  4. Poco X8 Pro Series Global Launch Date Leaked Ahead of Anticipated Debut: Expected Price, Specifications
  5. MacBook Neo Geekbench Scores Indicate It Performs on Par With iPhone 16 Pro Max
  6. Xiaomi Testing Experimental AI Agent Miclaw, Can Perform Complex Tasks Across Devices
  7. Dear Radhi OTT Release: Where to Watch the Tamil Thriller Online?
  8. With Love Now Streaming on Netflix: Know Everything About Plot, Cast, and More
  9. Kaattaan OTT Release Date Confirmed: When and Where to Watch Vijay Sethupathi Starrer Online?
  10. OnePlus 15T Display Size, Ultrasonic Fingerprint Sensor Confirmed; Geekbench Listing Hints at Chip, Memory
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.