Flaw allows malicious app to bypass VPN configuration in Android 4.3, 4.4
A VPN bypass flaw discovered last week in Android Jelly Bean 4.3 also exists in the latest version of Google's mobile operating system, KitKat 4.4, Israeli researchers say.
Ben Gurion University researchers found the initial bug and then did further testing to determine its existence in KitKat. The researchers published their latest findings on the university's Cyber Security Labs blog.
Google did not respond to a request for comment, but security experts said Wednesday the bugs in both versions of Android should be fixed quickly. "I believe this is a serious issue," Paul Henry, a senior security instructor at the SANS Institute, said. Because of differences in the OS versions, the same exploit code cannot be used, the researchers said. However, what can be accomplished by malware is the same.