Seems that a
new Android vulnerability has been found that affects 99% of 'droids and could make your phone open to anything from snooping to a complete take over
All Android apps contain a crytographic signature that ought to be invalidated if a legitimate app is tampered with - e.g. 'infected' with a virus - after distribution. Your phone checks the signature and will refuse to install an app if it's signature is invalid.
This vulnerability means that the apps can be amended without invalidating the signature which in turn means that kosher apps can be 'infected' with dodgy code and your phone will happily install them.
Unfortunately, individual manufacturers will need to fix their firmware
and distribute the fix to
all phones running any version of Android from 1.x on - good luck anyone with a non-current phone
On the upside, Google have fixed Play so no infected apps can be distributed from there which means that, so long as you avoid 3rd party app stores, you should be - relatively - safe.