Skip to main content

Google rolls out security fix for Android data leak flaw

Google Android LogoA report surfaced earlier this week indicating that there’s a security risk affecting 99 percent of Android devices. That’s a pretty large number, and Google unsurprisingly responded swiftly, bringing the hammer down on the Android OS with a shiny, new fix.

News of the potential security issue came from research conducted at Germany’s University of Ulm. The flaw affects all versions of Android version 2.3.3 or older and stems from the authentication protocol ClientLogin. Basically, your average app communicates with Google to request an “authentication token” (authToken) by sending over the device user’s account name and password via a secure connection. The authToken lives for no more than 14 days, but it can be reused during that time and there’s a danger of it being captured by an “adversary,” who would then be able to extract any personal data exchanged by the app. Follow the source link for a much more knowledgeable (and technical) explanation, but that’s the basic gist of it.

Not the cataclysmic security flaw that the “99 percent of all devices are affected” statistic might suggest, but worrisome enough. Especially in this particular moment, when many of us are acutely aware of private data security concerns following Sony’s recent troubles. The security update from Google has already started to roll out, as the company revealed in a statement to Digital Trends:

“Today we’re starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts. This fix requires no action from users and will roll out globally over the next few days.”

Adam Rosenberg
Former Digital Trends Contributor
Previously, Adam worked in the games press as a freelance writer and critic for a range of outlets, including Digital Trends…
Apple just admitted defeat to Android phones
A Google Pixel 8 Pro in Porcelain (left) with an iPhone 15 Pro in Blue Titanium held in hand.

For years, Apple’s smartphones have held a decisive upper hand over Android devices in one crucial aspect: the longevity of the software support cycle. In a nutshell, as long as your phone keeps getting updates, it will run just about fine.

Brand assurances play a crucial role in buyer behavior, as long-term update support means your phone will not only get new tricks but also security flaws patched. Notably, Apple is not into the habit of quoting how many years it will offer software support for each device, but it has held the crown for a while.

Read more
Google’s Gemini AI app gets a wider release. Is your phone on the list?
Google Gemini app on Android.

More people can now use and enjoy the Google Gemini AI app on their smartphone, as the company has expanded the list of regions where the Android version of the app is available through the Google Play Store. Specifically, it has launched the Android app in the U.K. and Europe, opening the service up far beyond its start in the U.S., where it was released in February.

What’s more, Google says Gemini will soon be available to iPhone owners, as the AI chatbot will appear on iOS in the next few weeks. It won’t be a standalone app though, as Gemini will instead work through the official Google app that can be downloaded now through the Apple App Store.

Read more
AT&T just made it a lot easier to upgrade your phone
AT&T Storefront with logo.

Do you want to upgrade your phone more than once a year? What about three times a year? Are you on AT&T? If you answered yes to those questions, then AT&T’s new “Next Up Anytime” early upgrade program is made for you. With this add-on, you’ll be able to upgrade your phone three times a year for just $10 extra every month. It will be available starting July 16.

Currently, AT&T has its “Next Up” add-on, which has been available for the past several years. This program costs $6 extra per month and lets you upgrade by trading in your existing phone after at least half of it is paid off. But the new Next Up Anytime option gives you some more flexibility.

Read more