Android apps vulnerable to Heartbleed: What's the risk and how to mitigate it?

  • Android 4.1.1 and apps that integrate the vulnerable OpenSSL are the most vulnerable; the default system is generally not exposed.
  • Investigations found thousands of apps connecting to compromised servers and 1.300 potentially vulnerable ones, with Lifestyle and Leisure being the most affected.
  • Many scanners don't detect them correctly; update Android and your apps, and change passwords only when the service confirms the patch.
  • Developer efforts have drastically reduced exposed downloads, but good security practices are still a good idea.

Android apps vulnerable to Heartbleed

A good number of web pages have been protected against the threat of Heartbleed, a security hole that allows access to users' private data. Regrettably, Android has also fallen prey to this error and several apps have not yet been patched, putting users and above all, their privacy at risk.


Add as preferred source