Google’s Android software development kit is using several outdated and vulnerable open-source image processing libraries, according to an alert from Core Security, a company that specializes in penetration-testing software.
In an advisory released Mar. 4, Core Security identified several exploitable heap overflows and integer overflows haunting Android, Google’s software stack for mobile devices that includes an operating system, middleware and key applications.
In all, Core Security lists eight different vulnerabilities identified in the Android SDK, which is currently in beta.
On the Android Developers Blog, developer advocate Jason Chen confirmed “a security issue involving handling of image files” that has been fixed with the latest with the recently updated Android m5-rc15.
Although the Android project is currently in a development phase and has not yet made an official release, Core Security noted that several mobile chip vendors have released prototype phones built with early releases of Android.
“Several vulnerabilities have been found in Android’s core libraries for processing graphic content in some of the most used image formats (PNG, GIF an BMP). While some of these vulnerabilities stem from the use of outdated and vulnerable open-source image processing libraries other were introduced by native Android code that use them or that implements new functionality,” Core Security warned.
The company has released proof-of-concept code to show that the vulnerabilities can be exploited to take “complete control” of a phone running the Android platform.
The proof-of-concept has been used successfully on the emulator included in the SDK, proving the possibility of running code on Android stack (over an ARM architecture) via a binary exploit.
Core Security said Android SDK m3-rc37a and earlier are vulnerable to several bugs in components that process GIF, PNG and BMP images, and Android SDK m5-rc14 is vulnerable to a security bug in the component that process BMP images.
In a Vendor Statement section of the advisory, the Google-backed Open Handset Alliance says there will be many changes and updates to the platform before Android is ready for users. These changes are expected to include full security review.

AI thrives on data but feeding it the right data is harder than it seems. As enterprises scale their AI initiatives, they face the challenge of managing diverse data pipelines, ensuring proximity to insights, and supporting a growing range of workloads. In this episode, Corey Knowles speaks with Vrashank Jain, lead product manager for Dell’s AI Data Platform, about how businesses can overcome these hurdles with solutions that simplify data management, enhance performance, and unlock the full potential of their AI investments.

In this episode of eSpeaks, Jennifer Margles, Director of Product Management at BMC Software, discusses the transition from traditional job scheduling to the era of the autonomous enterprise.

eSpeaks’ Corey Noles talks with Rob Israch, President of Tipalti, about what it means to lead with Global-First Finance and how companies can build scalable, compliant operations in an increasingly uncertain world. They explore how automation, AI, and integrated platforms are helping finance teams tackle today’s biggest challenges, from cross-border compliance and FX volatility to […]
-
Latest News - Resources Resource HubsFeatured ResourcesLink to The Real AI Power Play: Who Controls Your Enterprise Data Layer?
The Real AI Power Play: Who Controls Your Enterprise Data Layer?IT and data teams were promised that AI would make work easier. Instead, it's created new layers of complexity.Link to Building the Backbone of Agentic AI with Trusted, Context-Rich Data
Building the Backbone of Agentic AI with Trusted, Context-Rich DataIn this 10-minute take video, Reltio Principal Solutions Consultant Guy Vorster explains how organizations can overcome fragmented data challenges to power AI agents.Link to IHG scales real-time, trusted data across global brands
IHG scales real-time, trusted data across global brandsAccelerating time to value while powering data-driven engagementLink to Dell’s Vrashank Jain on The Data Problem That Could Break Your AI
Dell’s Vrashank Jain on The Data Problem That Could Break Your AIAI thrives on data but feeding it the right data is harder than it seems. As enterprises scale their AI initiatives, they face the challenge of managing diverse data pipelines, ensuring proximity to insights, and supporting a growing range of workloads. In this episode, Corey Knowles speaks with Vrashank Jain, lead product manager for Dell’s AI Data Platform, about how businesses can overcome these hurdles with solutions that simplify data management, enhance performance, and unlock the full potential of their AI investments.
Link to BMC’s Jennifer Margules on Intelligent Enterprise Orchestration
BMC’s Jennifer Margules on Intelligent Enterprise OrchestrationIn this episode of eSpeaks, Jennifer Margles, Director of Product Management at BMC Software, discusses the transition from traditional job scheduling to the era of the autonomous enterprise.
Link to Global-First Finance: Building Scalable, Compliant Operations in an Uncertain World
Global-First Finance: Building Scalable, Compliant Operations in an Uncertain WorldeSpeaks’ Corey Noles talks with Rob Israch, President of Tipalti, about what it means to lead with Global-First Finance and how companies can build scalable, compliant operations in an increasingly uncertain world. They explore how automation, AI, and integrated platforms are helping finance teams tackle today’s biggest challenges, from cross-border compliance and FX volatility to […]
-
Artificial Intelligence -
Video -
Big Data & Analytics -
Cloud -
Networking - Cybersecurity Cybersecurity
- Applications Applications
- IT Management IT Management
- Storage Storage
- Mobile Mobile
- Small Business Small Business
- Development Development
- Database Database
- Servers Servers
- Android Android
- Apple Apple
- Innovation Innovation
- PC Hardware PC Hardware
- Reviews Reviews
- Search Engines Search Engines
- Virtualization Virtualization
-
- Blogs Blogs
- Events Events