Independent security researcher Rafay Baloch has written about a security bug in the Android Browser app that allows one website to steal data from another. He found a way of sucking in content from another site into an IFRAME, and then reading Document Object Model data from that frame using some JavaScript trickery. Android 4.4 (KitKat) doesnt have it by default, but older versions of Android do come with it. The bug might well be there to stay, unless your phone vendor decides to offer a firmware update.”]

