Fixes to the Android fork CyanogenMod cast light upon the “masterkey” flaw and revealed it to be a simple trick of putting two same-named files in an archive. The challenge for Google is how to mitigate any exploitation and get updates to users.
Read more at The H