HTC confirms hole in its Android phones

Share this article:

HTC on Tuesday confirmed a gaping vulnerability in its Android phones that could be exploited by a third-party to steal personal information from users.

The company said it was not aware of any customers yet impacted by the flaw, but that it was "diligently" working on a fix.

"Following a short testing period by our carrier partners, the patch will be sent over-the-air to customers, who will be notified to download and install it," the statement said.

The flaw, affecting several HTC Android smartphone models, was discovered by researcher Trevor Eckhart, who alerted the company about it on Sept. 24 and received no response for five days before going public with the issue on Friday, according to the blog AndroidPolice, which first reported the news.

The bug stems from a recently added program, HTCLoggers.apk, which logs large amounts of information from the phones, according to Eckhart. The program enables any third-party app that requests permission to connect to the web to easily access data that has been logged. This information includes user accounts, email addresses, GPS locations, SMS data, phone numbers and system logs.

HTC Android phones, including the EVO 3D, EVO 4G and Thunderbolt, among others, are affected, Eckhart said.

In its statement, HTC advised customers to "use caution when downloading, using, installing and updating applications from untrusted sources."

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

Kevin Mitnick to sell zero-day exploits

Kevin Mitnick's new venture will develop and procure zero-day exploits, then sell them for $100,000 or more.

FBI warns of potential cyber attacks launched by ISIS hacktivists

Following U.S. military airstrikes in the Middle East, the FBI has issued a warning regarding possible cyber threats aimed at U.S. networks and critical infrastructure by hacktivists in support of ISIS.

Report: 75 million records compromised so far in 2014

Report: 75 million records compromised so far in ...

An updated report indicates that since this time last year, breaches have increased by 29.4 percent, with 568 breaches occurring this year.