Tag Archives: WebView

Google to remove support for old versions of Android WebView

Earlier this week, Google announced that they will no longer release patches for WebView versions JellyBean and older.

WebView is a core Android component which is used to display web pages on mobile devices and has been a target for exploitation from hackers. Google’s decision to stop patching old versions of WebView could potentially leave millions of users at risk.

Here is a video of Elad Shapira, one of our mobile security experts, executing an exploit on WebView.

Video

Demonstrating a WebView exploit

 

How many people are affected?

While it’s quite common for companies to pull support for legacy products, Android is a special case as there are many devices still running old versions of the operating system.

In fact, the latest mass-market version of Android (4.4, KitKat)- only makes up 40% of the overall Android market meaning that up to 60% of all Android devices might receive no further WebView patches.

Image courtesy of  securitystreet

 

Why does this matter?

Support in the form of patches and security fixes are one of the most important ways to keep our devices safe. New vulnerabilities in operating systems and apps are found all the time and can cause privacy and security concerns for end users.

Software developers use security patches to protect fix these vulnerabilities and protect users from harm.

Having said that, Android is by its very nature open source, so there is always the possibility for newly discovered vulnerabilities to be patched by the Android community but that is a Band-Aid fix at best.

What can be done to help you keep safe?

The most straightforward step to help stay safe (and the one Google is likely hoping we all adopt)  is to upgrade to the latest version of Android. For some however, this would prove prohibitively expensive and would require the purchase of a new device.

Those with recent devices should be able to upgrade to KitKat without much problem and people with brand new devices should be on version 5, Lollipop.

As a complementary measure, having a fully updated security app running on your device will help keep you safe from most scams and malware.