As reported in Experts Found a Unicorn in the Heart of Android there is a major security vulnerability in Android.
Android uses a media library called Stagefright written in C++ for efficiency. Stagefright has a vulnerability that allows a specially-crafted media file sent in a MMS message to remotely execute code. A skilled attacker could even delete the message before it is seen. In other words, your phone could be compromised without you even knowing it.
Google has already patched Android but it will take time for the update to get to all devices. The device’s manufacturer must send the update. Older (than 18 months) devices might not even get the update.