LG G3 'Snap' Vulnerability Leaves Owners At Risk of Data Theft (betanews.com)
Mark Wilson writes: Security researchers have discovered a vulnerability in LG G3 smartphones which could be exploited to run arbitrary JavaScript to steal data. The issue has been named Snap, and was discovered by Israeli security firms BugSec and Cynet. What is particularly concerning about Snap is that it affects the Smart Notice which is installed on all LG G3s by default. By embedding malicious script in a contact, it is possible to use WebView to run server side code via JavaScript. If exploited, the vulnerability could be used to gather information from SD cards, steal data from the likes of WhatsApp, and steal private photos.
This is also why I only have a Nexus, most of these security issues are with third party android handsets with most never getting timely updates (Google really needs to fix this issue). I buy a Nexus for the same reason you get an iphone, up_to_date_security_patches. Yes many of you will say "but, but you can use xyz third party android roms and they don't have this issue". The issue with that is android is now mainstream so 98% of android device owners do not have the ability or the knowledge to change the firmware. The fix is simple, Google needs to start enforcing better security policies on companies who want too use the Google android(tm) brand. People are just going to get sick of not having updates and move to GASP! Windows or Apple.
These are all before 9.2 so have been patched on all devices from the 4S onwards. My Note 2 is still on KitKat and has numerous security vulnerabilities which Samsung don't give a shit about fixing.