After even Apple fixed their software to reject certificates issued by Diginotar, Android is (one of?) the last platform that did not issue a fix. Given the fact that this whole affair started, because Google users' confidentiality was compromised by the Iranian government using a false certificate from DigiNotar, this is quite surprising.