Severe Deserialization Vulnerabilities Found In Android, 3rd Party Android SDKs
An anonymous reader writes: Closely behind the discoveries of the Stagefright flaw, the hole in Android's mediaserver service that can put devices into a coma, and the Certifi-gate bug, comes that of an Android serialization vulnerability that affects Android versions 4.3 to 5.1 (i.e. over 55 percent of all Android phones). The bug (CVE-2015-3825), discovered by IBM's X-Force Application Security Research Team in the OpenSSLX509Certificate class in the Android platform, can be used to turn malicious apps with no privileges into "super" apps that will allow cyber attackers to thoroughly "own" the victim's device. In-depth technical details about the vulnerabilities are available in this paper the researchers are set to present at USENIX WOOT '15.
I dropped the entire Google platform last year. It's fantastic sitting back and watching the Google fanboy's house of cards come crashing down.
Sent from my Windows Phone.
That's what I did, because I know that iOS is secure, that is... secure comparatively speaking to the steaming pile of crap that Android is. I'm not saying that iOS is 100% secure, no, that's not at all what I'm saying. What I am saying is that comparatively speaking, iOS seems more secure than Android.