The applications took advantage of known vulnerabilities which dont affect Android versions 2.2.2 or higher. The only information the attacker(s) were able to gather was device-specific (IMEI/IMSI, unique codes which are used to identify mobile devices, and the version of Android running on your device). But given the nature of the exploits, the attacker could access other data, which is why weve taken a number of steps to protect those who downloaded a malicious application: You will receive an email from [email protected].”]
Source: http://googlemobile.blogspot.com/2011/03/update-on-android-market-security.html

