Google pulled at least 50 malware-infected mobile apps from the Android Market last week. After plenty of criticism, the company is now vowing to tighten up security on the platform.
The malware took advantage of known vulnerabilities that don’t affect Android versions 2.2.2 or higher, according to Google. For affected devices, Google believes that the only information the attackers were able to gather was device-specific.
Although it appears there was no major identity theft — and although Google responded within minutes of being notified that there were malicious applications published to Android market — some analysts are beginning to question the brand’s ability to secure itself.
“Google is on track to become the Microsoft of mobile,” said Greg Sterling, principal analyst at Sterling Market Intelligence. “And, just as Microsoft’s larger PC market share attracted hackers and computer viruses, that’s the danger for Android as it becomes the world’s number two mobile platform.”
The Android Fix
Google is responding to public concerns by publishing the steps it has taken to protect people who downloaded a malicious app. First of all, Google removed the malicious applications from the Android Market, suspended the associated developer accounts, and contacted law enforcement about the attack, said Rich Cannings, Android Security Lead at Google.
“We are remotely removing the malicious applications from affected devices. This remote application removal feature is one of many security controls the Android team can use to help protect users from malicious applications,” Cannings continued.
Google is also pushing an Android Market security update to all affected devices. The update undoes the exploits to prevent the attackers from accessing any more information from affected devices.
“If your device has been affected, you will receive an e-mail from [email protected] over the next 72 hours. You will also receive a notification on your device that “Android Market Security Tool March…