Android under fire again for poor vulnerability patching

More than half of Android devices worldwide have unpatched vulnerabilities

Carriers and device managers continue to be slow at patching Android devices, as the number of malware targeting the mobile operating system soars, recent studies show.

Two security vendor reports released last week point to the continuation of a longstanding problem with Android devices. The platform remains the prime target for malware, yet there's no easy way for users to keep the software up to date with the latest patches.

In the latest findings, Duo Security collected results from 20,000 Android devices that users had scanned with the company's X-Ray vulnerability assessment tool, which became generally available a couple of months ago.

Based on the results, Duo estimates that more than half of Android devices worldwide have unpatched vulnerabilities.

"We feel this is actually a fairly conservative estimate based on our preliminary results, the current set of vulnerabilities detected by X-Ray, and the current distribution of Android versions globally," Jon Oberheide, Duo's chief technology officer, said in a blog post.

[In depth: Mobile device security - 5 questions to ask when creating policy (includes video)]

Duo's findings are in line with a Bit9 report released this year. The security vendor found that 56% of Android phones in the marketplace in 2011 were running out of date and insecure versions of the software. Device manufacturers found to be slow in upgrading phones included Samsung, HTC, Motorola, Sanyo, LG and Sony.

In the meantime, Sophos reported last week that the number of newly discovered malware for Android has increased 41 times this year over 2011, based on samples collected by the vendor's lab.

Almost half of the increase comes from a family of toll fraud malware targeting Eastern European markets. Toll fraud is when a malicious app secretly sends text messages from a hijacked phone to paid services. Cybercriminals typically get a cut of the generated revenue.

Closer to home, the biggest threat in the U.S. is new apps that contain aggressive advertising tactics that cross the privacy line. The more aggressive apps place links for sponsored apps in the phone's launcher area, display advertising even when the app is not running and send the user's personal information to the advertising server. These tactics are often in violation of Google's ad policy for Android.

Overall, the studies reinforce what security experts have known for years: Android fragmentation is an ongoing risk for users.

Unlike iOS, which only Apple controls on the iPhone and iPad, the Android market has many vendors using many versions of the platform. This translates into a mishmash of patching strategies made more complicated by carriers responsible for pushing out updates.

"Some carriers push out patches sooner than others, and some users install patches sooner than others," said Chenxi Wang, an analyst for Forrester Research. "No one should really be surprised that more than half of Android devices have unpatched flaws. Would the situation get better any time soon? I don't see it."

While no easy solution is in sight, Android malware is on the rise, which increases the risk to users with unpatched phones, Wang said. However, mobile malware is not at the level of maturity as malicious apps built to exploit vulnerabilities in PCs, so the danger to Android users is far less.

"You can survive not having updated your phone OS for some time, but you cannot survive if you don't update your [antivirus] or OS patches for your PC," Wang said.

The level of risk to Android users is a longstanding debate in the industry. While antivirus vendors are a steady source of threat research, Google has said they are hyping the risk to sell their products.

Read more about wireless/mobile security in CSOonline's Wireless/Mobile Security section.

Join the CSO newsletter!

Error: Please check your email address.
Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Antone Gonsalves

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts