At the time of logging in the authentication token issued by Google remains valid for 15 days and can be used again on Google Calendar, which doesn't use https. Meanwhile, the username and password can be intercepted.
Close to 99 per cent of all Android devices are prone to data theft, especially of the username and passwords of Google services, German researchers have reported.
It was found that Android devices running on 2.3.3 or older versions are particularly susceptible as the client login authentication process used in these versions is insecure.
In fact, the vulnerability exists not just for Google apps but for any apps that don't use a ClientLogin protocol (the protocol for logging in to your Google account) only on https (secured).