Jump to content

Android Jelly Bean, Kit Kat vulnerable to security flaw

mgsstar
A new flaw was recently found in the Google Android Jelly Bean and Kit Kat OS flavors, with the "critical flaw" compromising the virtual private network (VPN) in the Android OS.
 
Compromised devices allow cybercriminals to monitor communication after VPN traffic is sent to a different network address.
 
The flaw, which was found in India, can be successfully remedied by installing updates from OEM manufacturers, the CERT-In team says. Installing anti-virus and anti-malware protection on the device should help add additional layers to prevent Android exploits from causing problems.
 
"A critical flaw has been reported in Android's (virtual private network) VPN implementation, affecting Android version 4.3 and 4.4 which could allow an attacker to bypass active VPN configuration to redirect secure VPN communications to a third party server or disclose or hijack unencrypted communications," said the Computer Emergency Response Team of India (CERT-In).
 

 

Source:http://www.tweaktown.com/news/35912/android-jelly-bean-kit-kat-vulnerable-to-security-flaw/index.html

 

This is pretty dangerous that they can change a VPN that someone is using to a malicious one. Hope Google and phone manufacturers will release fixes ASAP. Never used VPNs on Android because got annoyed because of the PIN that it required when using a VPN.

 

Hello and Welcome to LTT Forum!


If you are a new member, please read the rules located in "Forum News and Info". Thanks!  :)


Linus Tech Tips Forum Code of Conduct           FAQ           Privacy Policy & Legal Disclaimer

Link to comment
Share on other sites

Link to post
Share on other sites

Good thing I don't expect a secure connection on a mobile device then :ph34r:

Case: Meatbag, humanoid - APU: Human Brain version 1.53 (stock clock) - Storage: 100TB SND (Squishy Neuron Drive) - PSU: a combined 500W of Mitochondrial cells - Optical Drives: 2 Oculi, with corrective lenses.

Link to comment
Share on other sites

Link to post
Share on other sites

Hope Google and phone manufacturers will release fixes ASAP.

Manufacturers and Android updates - isn't it  something that doesn't fit in one sentence...

Link to comment
Share on other sites

Link to post
Share on other sites

Manufacturers and Android updates - isn't it  something that doesn't fit in one sentence...

I guess so lol. Should have meant Google releasing an update so phone manufacturers will implement it.

Hello and Welcome to LTT Forum!


If you are a new member, please read the rules located in "Forum News and Info". Thanks!  :)


Linus Tech Tips Forum Code of Conduct           FAQ           Privacy Policy & Legal Disclaimer

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×