Application security

176 vulnerabilities discovered in Samsung mobile apps

18 zero-day flaws impact Samsung Android handsets, wearables and telematics

Security researchers from Oversecured have uncovered 176 vulnerabilities, including critical flaws, within Samsung's preinstalled mobile applications. These issues could have led to account takeovers, code execution, and traffic hijacking, affecting hundreds of millions of devices globally, based on information published by Tech Radar.

The vulnerabilities were found in Samsung's proprietary system apps, which cannot be uninstalled by users and operate outside the protection of Google Play Protect. Flaws identified included the ability to take over Samsung accounts with a single click, execute arbitrary code through specially crafted image files, and hijack network traffic via DNS manipulation. Path traversal vulnerabilities also allowed for writing arbitrary files to the file system.

Oversecured disclosed these findings to Samsung, which has since patched all reported issues. The context of these vulnerabilities is significant because preinstalled apps have elevated privileges, and a single flaw can impact a vast number of devices distributed through a single vendor.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds