Android Update Patches OpenSSL Bug

Thanks to a minor system update, Android users can now rest a bit easier. Android version 4.4.4 patches an exploitable OpenSSL flaw, making mobile devices much safer from potential security breaches.

Ars Technica gathered a few separate points of data on the update, which Google unveiled very quietly. The new update brings Android's version up to 4.4.4, and goes by the charming, easy-to-remember name of KTU84P.

MORE: 13 Security and Privacy Tips for the Truly Paranoid

Only Google's own Nexus devices have access to the update at present, which Nexus owners can either download from the Google Developers page or wait until it hits their devices automatically within the next few weeks. In our own tests, we found that a Nexus 10 had not yet received the update, and did not find it when we prompted it to search.

Android 4.4.4 addresses a vulnerability in the OpenSSL protocol. In layman's terms, OpenSSL is a common method that websites and programs use to encrypt user information. A security flaw dubbed CVE-2014-0224 was able to exploit a piece of OpenSSL code that allowed it to decrypt user information while it was in transit online between the user and the receiving party. The new Android update will render that particular bug moot.

According to Sascha Prüter, an Android engineer at Google, the update will also address a number of other minor security concerns. Android developers can expect to see an open source version of the code within the next two days.

All in all, 4.4.4 is not the most exciting update you'll ever install on your Android device, but it may help keep you safe when the next big security breach hits. Those who don't have Nexus devices will have to wait, though. Generally, mobile providers wait much longer than Google to provide Android updates, and for older phones, they may not provide updates at all.

Follow Marshall Honorof @marshallhonorofand on Google+. Follow us @tomsguide, on Facebook and on Google+.

TOPICS
Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Latest in Android Phones
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
vivo x200 ultra camera array
Vivo’s next premium phone could have a camera unlike anything we’ve seen before — here’s how
Google Pixel 9a with thumbs up and thumbs down icons
Google Pixel 9a — 5 reasons to buy and 3 reasons to skip
Latest in News
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
  • house70
    "All in all, 4.4.4 is not the most exciting update you'll ever install on your Android device, but it may help keep you safe when the next big security breach hits. Those who don't have Nexus devices will have to wait, though. Generally, mobile providers wait much longer than Google to provide Android updates, and for older phones, they may not provide updates at all."

    Actually, this could not be further from the truth. OEMs implement their own proprietary kernels, so some exploits might be valid for some devices while other devices are immune from same exploits. Google HAD to go up on their own AOSP-based kernel, since it involves a kernel modification. Other manufacturers might not have to do the same, and it would not be the first time that while some devices were vulnerable, others were immune. IMO, 4.4.4 just includes a couple security features ommited from 4.4.3.
    Last but not least GPE devices have received any/all applicable updates within a couple weeks from Nexus devices.
    Can't really have great expectations from a website that missed the release of 4.4.3 completely, like it never happened (let alone publishing any change-logs or anything pertaining to the subject). If you want to keep up with Android news this is not the best place to be. iOS, however, is extensively covered . To each his/her own.
    Reply