Any operating system could have security flaws. Unlike Apple which maintains a controlled environment on it's apps Android has allowed users the opportunity to install applications from other application markets or sources. A new vulnerability which can been discovered shows a flaw in the Android operating system which causes pop ups to appear when an infected application is running. This flaw could also be used for phishing attacks on your device. This means that you could loose important bank information or passwords to sensitive data as this malware can mimic the app asking for your credentials.
Users be warned. Be careful when you click the 'Add unknown sources' option unless you are sure about what you are doing.
source - CNET