Google has begun distributing a patch to its Android mobile phone operating system, an early test for how the company can respond and how well the infrastructure works to distribute and install updates.
For the Android phone people are using, a T-Mobile G1, the update is smoother than the process by which the software problem came to light publicly on October 24.
The handset gives a message: "A system update is available," and a choice to update now or later. When you click the button to begin the update, it downloaded new software, which takes a few minutes, then installs it, then resumes working with no hitches.
The patch fixes the highly publicized security problem with Android's Web browser and makes a few other minor changes, according to a Google spokesman.
The researchers--Charlie Miller, Mark Daniel, and Jake Honoroff of Independent Security Evaluators--called the Android Web browser flaw serious, but Google said its severity was mitigated by Android's design, which restricts each program to its own area.
Earlier, Google appealed for what it called "responsible disclosure" of security vulnerabilities--in other words, a grace period to fix problems before they're made public to reduce the likelihood an attacker will get a chance to exploit a vulnerability. There's an ages-old tension between companies that want to fix their products and security researchers who want to get the word out, in part because attackers also are trying to find the vulnerabilities.
Source: CNet news