it's no longer viable to "safely" patch vulnerable, pre-Android 4.4 versions of WebView (a framework that lets apps show websites without a separate browser) to prevent remote attacks. The sheer amount of necessary code changes would create legions of problems, he claims, especially since developers are introducing "thousands" of tweaks to the open source software every month.
He does offer some suggestions though (and engadget summarizes them) on how to avoid or mitigate issues if you are on an older version of Android.