Security duo finds another pair of vulnerabilities in Android
L33tdawg: Don't forget Riley Hassell's much anticipated talk on Android at next month's HITBSecConf in Malaysia
Remember the duo who released an Angry Birds spoof application last fall in effort to highlight some of Android's vulnerabilities? If so, perhaps you also recall hearing that Google had to implement the remote kill feature in Android about the same time. Well, those guys are back and, judging by their latest finding, things still don't look to be all that secure.
A quick primer: Jon Oberheide and Zach Lanier put an app in the Android Market back in November 2010 that was a proof-of-concept that malicious developers could install additional applications without a user's knowledge. Google was quick to recognize the situation and pulled the "malicious" app, subsequently issuing a fix for the vulnerability.
Fast forward to present day where the security-minded pair have identified two new vulnerabilities in Android. Although both have been shown to Google, neither of the holes have been patched at the time of this writing.
