A quarter of Android users are running the latest version, Android 4.4. Everyone else is using older versions.
Their systems have not been updated as device manufacturers cannot provide timely updates to devices. This often creates security problems. A recently discovered security flaw in the Android Browser reminds us why the difficulty of manufacturers to provide updates is a significant problem. The Android Browser is the default web browser for Android devices. This changed after Android version 4.2 when Chrome became the default browser . Google switched to Chromium from Android 4.4, which means that anyone not using version 4.4 is exposed to the bug.
What causes the vulnerability
When you visit a website, you can expect it to serve you its content quickly. A script running on the website should, for example, not be able to modify the content of another website. This is the flaw found to be occurring in the Android Browser.
Same Origin Policy (SOP) is a security mechanism designed to prevent JavaScripts from being executed from one website to another. JavaScripts running on malicious sites should not be able to retrieve data from “good” sites.
This happens in the Android Browser when the browser is used by applications that could potentially steal sensitive data. Data such as cookies can be stolen by this vulnerability.
Check your device
To check if your device is vulnerable, visit the following website and click the test button to find out if you are affected.
If you get a pop-up message that browser is vulnerable, be sure to change browsers.
The problem
Google is working on a patch to fix the problem. However, the release of the patch to the end user will be complicated. The main reason is that for this kind of updates the responsibility lies with the device manufacturer.
Taking into account that support for devices usually ends after two years, it is unlikely that all vulnerable devices will receive the update.
To make matters worse, switching to another browser like Firefox or Chrome on affected devices only solves part of the problem. Although the browser will be secure, apps running on the device may still use the default browser, which is of course the Android Browser.


