Google Patches Heartbleed Across Services, But Millions Of Android Devices Remain At Risk

Apr 14, 2014

Google has moved to patch up its apps and services to protect them against the Heartbleed bug, and the company has said that its mobile OS is immune – save for one particular version of Android.

Google was quick to respond to the news of the bug breaking last week, as you'd expect, and swiftly applied patches across its major services including Gmail, YouTube, Wallet, Play, Apps, App Engine, AdWords, DoubleClick, Maps, Maps Engine and Google Earth (oh, and that search engine thing it has, too).

Mountain View also noted that Android was immune to the Heartbleed flaw, save for one exception – Android 4.1.1.

That is, of course, a problem because patching Android isn't quite as simple as Google's other services. Google can concoct the patch swiftly enough, but getting it out to handset manufacturers and network operators, and subsequently rolled out to devices is a notoriously time consuming process. And that's time which they don't have now knowledge of the bug is widespread...

How many folks are still using Android 4.1.1? According to the latest stats from the Android developer page, 34 per cent of users are running Jelly Bean 4.1.x, and it's by far the most-used version of Google's OS.

Not all of those will be running version 4.1.1, but that still represents a big chunk of users – according to Bloomberg Google says it's less than 10 per cent of active Android users, but that could be up to 90 million folks.

Author: Darren Allan
View the original article here.
Published under license from