Google Ends Crucial Fixes for Android Jelly Bean

If you've got one of the 930 million or so Android devices that run 4.3 Jelly Bean or earlier, you may want to steer clear of the standard Android Web browser and any apps that can view websites. Google has discontinued updates for its WebView software on Android 4.3 and earlier, which leaves devices ripe for security exploits of every variety.

This information comes by way of SecurityStreet, the blog attached to Boston-based IT security company Rapid7. Security researchers Rafay Baloch and Joe Vennix have been hard at work developing exploits for Android systems and reporting them to Google. The only trouble is that Google isn't interested, at least when it comes to Jelly Bean or earlier.

MORE: Best Android Antivirus Software 2014

The Android security e-mail account replied to the vulnerabilities by explaining that it was only interested in issuing WebView patches for the two most recent versions of Android, 4.4 KitKat and 5.0 Lollipop. Since nearly one billion devices haven't been upgraded — or can't upgrade — to those, this could create a huge security risk. If two security researchers can create a whole host of exploits, it stands to reason that hundreds or thousands of hackers around the world could accomplish the same thing.

For those not familiar with the inner workings of Android, WebView is an integral part of the OS that leverages the built-in Web browser to display Web-based content on non-browser apps. When you see an ad pop up at the bottom of an app, it's probably using WebView.

Until Android 4.4 KitKat, WebView used the stock Android browser, commonly known as just "Browser." Google dumped that browser with KitKat and switched to Chrome, which many of its users were using as their primary browser anyway. It's easy to see why Google would want to keep Chrome current, but not expend too much time and energy on a system that's been phased out.

Unfortunately, users of older versions of Android don't have a lot of options, except to try to update their older phones or tablets to KitKat or Lollipop. (In the United States, cellular carriers often determine which version of Android a device will run.) Otherwise, they'll have to live with the WebView vulnerability and hope they're not exposed to any Web-borne malware — which is, admittedly, difficult to install in Android.

Google told Rapid7's Tod Beardsley that it would welcome third-party fixes for Browser-based WebView and roll them into future patches of Jelly Bean or earlier, but that it wasn't planning to develop any of its own.

Consider, also, an Android mobile security suite, which should spot and block most malware before it installs.

Marshall Honorof is a Staff Writer for Tom's Guide. Contact him at mhonorof@tomsguide.com. Follow him @marshallhonorof. Follow us @tomsguide, on Facebook and on Google+.

TOPICS
Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Latest in Android Phones
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
  • das_stig
    No comment on Google forcing manufacturers and ISP to give users updates to secure them online. Another case of got your money now FOAD, unless we can tempt you with a shiny new device that will be end of life 2 weeks later !
    Reply
  • smeezekitty
    I never use the standard Android browser but this is ridiculous.
    Jellybean isn't that old
    Reply