While Google likes to brag about how open Android is, the platform has become an increasingly open target for malware writers. Indeed, Google’s openness paved the way for malware writers to target apps in the Android Market, and Google has now had to resort to pulling 21 infected apps.
p
Google has confirmed the issue and said the apps contain malware that works to gain root access to a victim’s smartphone so it can snoop data and download additional code onto the handset — all without the user ever noticing.
p
We should point out that this vulnerability was patched with Gingerbread, meaning any device running Android 2.3+ should be fine, Aaron Gingrich of the Android Police, wrote in a blog post. The hole was fixed by Google, but it’s relatively useless since many phones aren’t yet running a version of Android that is protected.
p
subhead
Google’s Issues
/subhead
p
The malware drama isn’t exactly good news or good timing for Google. The company already faced a major public relations issue when millions of Gmail accounts went missing earlier this week. Indeed, Google Apps seem frequently to be the object of news stories that report glitches of one kind or another, according to Rob Enderle, principal analyst at The Enderle Group.
p
At RSA [the security conference], there was a talk about the fact that folks in China were pulling apps out of the marketplace, rewriting them, putting malware in them, and then rereleasing them on the web, Enderle said, pointing to a Tuesday evening report that the Droid Dream app was one of the affected applications on the Android Market store shelf.
p
When the Android Police notified Google, the search engine company was quick to respond, removing the apps within minutes. But the security issue could be a long-term problem for Google because, at least currently, anti-malware is not running…