Total Downloads

2,592,940

Total Files

9,206

Latest Update

10

Here's why all Samsung Galaxy phones (2014 or later) need to be updated now

Posted May 8, 2020 | Mobile | News


If you own a Samsung Galaxy handset produced in 2014 or later (which includes this year’s Galaxy S20 line), make sure that you install the monthly security update ASAP. That’s because of a “zero-click” vulnerability that could allow an attacker to load malicious code on your phone. According to ZDNet, Mateusz Jurczyk, a researcher with Google’s Project Zero team, discovered that on Samsung phones the process used by Android’s Skia graphic library to handle images in the Qmage graphic format (.qmg) has a bug that could be exploited by a bad actor.
To make matters worse, the zero-click designation means that the user does not have to interact with any particular part of the phone for the device to be exploited. When an Android phone is sent an image, it is redirected to the Skia image library for processing without the user’s knowledge. Jurczyk created a video of his proof of concept demo that showed the exploit in the Samsung Messages app. The researcher tested the exploit by repeatedly sending MMS messages to a Samsung handset while trying to bypass the protective ASLR (Address Space Layout Randomization) security technique. It took him 100 minutes and required him to send 50 to 300 MMS messages to bypass ASLR. “I have found ways to get MMS messages fully processed without triggering a notification sound on Android, so fully stealth attacks might be possible,” Jurczyk said.

While the researcher did his proof of concept test only on the Samsung Messages app, he said that in theory, the exploit is available on any app that can receive Qmage images from another device. While we don’t know whether the vulnerability was ever exploited by attackers, other Android manufacturers aren’t vulnerable to the bug because Samsung modified Android to support the Qmage image format; the latter was developed by another South Korean company named Quramsoft.

The recent security update disseminated by Samsung has this exploit designated as SVE-2020-16747 and Jurczyk’s report on the Project Zero site can be found here. Recently, Project Zero also found multiple vulnerabilities in Image I/O, used for parsing and working with image files on all Apple operating systems. These have been patched.

Security updates don’t seem exciting because they don’t deliver new features. Still, they are important to install right away because they can stop your phone from getting attacked by a bad actor looking to profit from his actions one way or another.



Source link

')
ankara escort çankaya escort çankaya escort escort bayan çankaya istanbul rus escort eryaman escort ankara escort kızılay escort istanbul escort ankara escort ankara escort escort ankara istanbul rus Escort atasehir Escort beylikduzu Escort Ankara Escort malatya Escort kuşadası Escort gaziantep Escort izmir Escort