10.06 AM Tuesday, 16 April 2024
  • City Fajr Shuruq Duhr Asr Magrib Isha
  • Dubai 04:36 05:52 12:21 15:49 18:45 20:02
16 April 2024

Heartbleed has Android covered, but BlackBerry?

Published
By Joseph George

First it was the OpenSSL on the web servers, then we got to know that mobile phones were the most vulnerable. Android had millions of its devices susceptible to the Heartbleed Bug, and now it turns out that even BlackBerry may not be immune to one of the most penetrating attacks ever.

The bug is so widespread that even BlackBerry, considered the most secure system, might have been compromised.

The company is now planning to release security updates to its BBM messenger on non BlackBerry devices – Android and iOS.

That was exactly what BlackBerry had feared prior to introducing BBM for Android and iOS. However secure BlackBerry devices and enterprise servers were, it feared that opening up to Android and to an extent iOS could make itself vulnerable to attack.

Now, according to Reuters, BlackBerry is now planning “to release security updates for messaging software for Android and iOS devices by Friday to address vulnerabilities in programs” exposed by the massive new security flaw.

The report quotes , BlackBerry senior vice president Scott Totzke as saying that the level OS risk though is very small and requires a very well timed complex attack.

Meanwhile, a new report by Ars Technica millions of Android devices could have been affected through the virus and, Android smartphones especially those running version 4.1.1 could have been compromised with their emails, messages, passwords including banking info and other info stolen.

According to it Android users could be lured “into a booby-trapped website that contains a cross-site request forgery or similar exploit that loads banking sites or other sensitive online services in a separate tab. By injecting malicious traffic into one tab, the attacker could possibly extract sensitive memory contents corresponding to the sites loaded in other tabs.”

Google had on Friday released a statement with regard to the vulnerability and said that it has applied to patches to key Google services such as Search, Gmail, YouTube, Wallet, Play, Apps, App Engine, AdWords, DoubleClick, Maps, Maps Engine, Earth, Analytics and Tag Manager. 

“Google Chrome and Chrome OS are not affected. We are still working to patch some other Google services,” it said.