http://www.phonedog.com/2010/11/29/andr ... d-exploit/There are now in-the-wild versions of the exploit.
A bug in the browser achitecture on the Android leaves it open to malicious websites, which can download a JavaScript script, which can pillage the devices data and send it to a C&C server. The script can harvest photos or data files for specific apps, currently.
It affects all current versions of Android (i.e. up to and including 2.2). The only current solutions are to use Opera Mobile (which will prompt before downloading) or to turn off JavaScript in the browser.
Google are aware of the problem and are working on a fix. When the hardware manufacturers and service providers get around to rolling out the patch is another matter...