Posts tagged vulnerability

samsung-galaxy-s-iii-flat3

Samsung has begun rolling out a software patch to address a major security flaw with its Exynos processor that leaves a handful of Android handsets vulnerable to attack. The update is first reaching Galaxy S III owners in the United Kingdom, but we would expect Samsung to be working hard to make this one available worldwide as quickly as possible.

Samsung has vowed to patch a major vulnerability discovered in its Exynos kernel that could allow certain Android devices to be wiped or bricked by a malicious application. The flaw was discovered earlier this week, and the Korean company promises to release a software update to address it “as quickly as possible.”

Developers have discovered a serious vulnerability with Samsung’s Exynos-powered smartphones — including its latest Galaxy S III and Galaxy Note II devices — that can provide attackers with access to all physical memory. The flaw leaves the handsets open to malicious apps that can access a user’s personal data, completely wipe their data, or worse, brick their handset.

Security expert Ravi Borgaonkar demoed a serious vulnerability in the way Samsung’s native browser and dialer app handle USSD codes and telephone links at the Ekoparty security conference. As shown by Ravi, malicious code could be used to trigger a factory reset without any forewarning or possible way of stopping it. Even more disturbing is the ability for such malicious code to perform a double whammy and also nuke the device’s SIM.