This article was published on February 9, 2012

Google is reportedly working to fix a major Google Wallet security flaw [Updated with response]


Google is reportedly working to fix a major Google Wallet security flaw [Updated with response]

Google is reportedly aware of and working to fix a major security issue relating to its Google Wall service on rooted Android phones.

Updated with Google’s response below.

A video posted by Zvelo (via 9to5Google) shows the PIN verification system on rooted devices that carry Google wallet can be cracked using an app that is freely available online.

Zvelo said on Wednesday that it immediately reported its findings to Google, which “agreed to work quickly to resolve it”, however the company says that Google “ran into obstacles” which meant that it is yet to release a fixed version of the app.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol' founder Boris, and some questionable AI art. It's free, every week, in your inbox. Sign up now!

If you’re running a rooted version of Android, you should seriously tread carefully until Google releases a fix for the problem. The password setting can easily the verification system can be overridden easily, even after the PIN is changed.

We’ve contacted Google for comment on the issue and will update the post with any feedback we receive.

Update: Google has provided The Next Web with a statement however there is no mention of whether it is working on a fix, which zvelo claims has since stalled.

The zvelo study was conducted on their own phone on which they disabled the security mechanisms that protect Google Wallet by rooting the device. To date, there is no known vulnerability that enables someone to take a consumer phone and gain root access while preserving any Wallet information such as the PIN.

We strongly encourage people to not install Google Wallet on rooted devices and to always set up a screen lock as an additional layer of security for their phone.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Also tagged with