Millions of Samsung Galaxy devices remotely exploitable

by
in security on (#BW4T)
Hackers can easily break into Samsung Galaxy phones and spy on the entire life of their users. A vulnerability in software on the phones lets hackers look through the phones' camera, listen to the microphone, read incoming and outgoing texts and install apps, according to researchers. The hack works by exploiting a problem with the Samsung IME keyboard, a re-packaged version of SwiftKey that the company puts in Samsung Galaxy keyboards. That software periodically asks a server whether it needs updating - but hackers can easily get in the way of that request, pretend to be the server, and send malicious code to the phone.

Researchers have confirmed that the exploit works on versions of the Samsung Galaxy S6, the S6 Edge and Galaxy S4 Mini. But it may also be active on other Samsung Galaxy phones, since the keyboard software is installed on more devices. It doesn't matter if users are using the keyboard or not. Samsung was notified about the vulnerability in December last year. Samsung is reported to have provided a patch to mobile network operators, who must push Android updates out themselves. There is little that owners of the phone can do beyond avoiding insecure WiFi networks. The most worrying part about this is that users can't stop their device from checking for updates. It may be time to grant superuser access to the device owner by default.

Re: Samsung for the WIN (Score: 1)

by pete@pipedot.org on 2015-06-22 14:44 (#C2Q8)

i read a bit more - the updates are supposedly for getting fresh word lists, and the like. and using another keyboard doesn't help, it still checks in the background.

why does it seem like some programmers go out of their way to ensure vulnerabilities can't be mitigated?
Post Comment
Subject
Comment
Captcha
In the number 9533995, what is the 4th digit?