Updated:10:26 AM EDT Sep 28

this is ggmania.com subsite All Samsung Galaxy Phones Since 2014 Are Vulnerable - TechAmok

All Samsung Galaxy Phones Since 2014 Are Vulnerable - [security]
04:12 PM EDT - May,10 2020 - post a comment

If you own a Samsung Galaxy handset that was released in the past six years, do yourself a solid and check for an over-the-air (OTA) software update. Left unpatched, every Galaxy phone dating back to 2014 is vulnerable to a so-called 'zero-click' bug related to Android's handling of the custom Qmage image format (.QMG). That means millions of Galaxy phones are affected by this, until patched with the latest security update from Samsung. Not to be overlooked, the vulnerability carries the highest 'Critical' rating, and could allow an attacker to run malicious code remotely. Part of the reason for the high severity rating is because vulnerable handsets can be exploited without any user interaction. Google's Project Zero team discovered the flaw and reported the issue to Samsung in January. It has been addressed in Samsung's May 2020 Security Bulletin, along with a bunch of other security issues. Mateusz Jurczyk, one of the security researchers with Project Zero, uploaded a proof-of-concept video to demonstrate the vulnerability

Left unpatched, and attacker could ping a target handset with multiple multimedia SMS (MMS) messages in repeated attempts to guess where the Skia library resides in a phone's built-in memory. Once that is determined, the attacker could send malicious code under the guise (to the phone) of a Qmage image. Jurczyk told ZDNet this typically entails between 50 and 300 MMS messages to discern the location and ultimately sidestep Android's ASLR (Address Space Layout Randomization) protection. And even though a high number of messages would usually trigger suspicion, they can be stealthily sent and processed by the target phone without any notifications. Fortunately, Samsung was relatively quick to roll out a fix after being alerted to the flaw. So again, if you own a Galaxy handset-either a recent one or dating all the way back to something like the Galaxy Note 4 or Galaxy Note Edge (both released in late 2014) - then head over into your device's settings and manually check for an update.

Short overview of recent news articles

NVIDIA GeForce 456.55 WHQL driver (Sep,28 2020 )

Resident Evil: Infinite Darkness CG series coming to Netflix (Sep,27 2020 )

Manufacturers response on NVIDIA RTX 3080 issues during gaming (Sep,26 2020 )

RTX 3090 8K Gaming (Sep,26 2020 )

Windows XP source code allegedly leaked online (Sep,25 2020 )

Here's How You Can Twist Your Eye Around Your Pupil (Sep,25 2020 )

Amazon Enters the Ring with Luna, its Game Streaming Service (Sep,25 2020 )

RTX 3080 Users Report Crashes to Desktop While Gaming (Sep,25 2020 )

Sega developing live-action Yakuza film (Sep,24 2020 )

Samsung Expands Galaxy S20 Series With More-Affordable Fan Edition (Sep,24 2020 )

Adobe Acrobat Reader can now Reformat PDFs for Easy Reading on (Sep,24 2020 )

Nokia Updates Entry-Level Phones (Sep,24 2020 )

GeForce RTX 3090 is only 10-15% faster than the RTX 3080 (Sep,24 2020 )

Model Builder Builds A Coliseum With 22,000 Dominos (Sep,22 2020 )

What's Inside $18,000,000 Luxury Doomsday Bunker? (Sep,22 2020 )

WeChat and TikTok Still Available in US; Future Uncertain (Sep,22 2020 )

NVIDIA Responds to Criticism Surrounding the RTX 3080 Launch (Sep,22 2020 )

World's Largest Devil's Toothpaste Explosion (Sep,20 2020 )

Apple One Bundles Apple Services, Including new Apple Fitness+ (Sep,20 2020 )

Apple Watch SE Starts at $279 (Sep,20 2020 )

Apple Watch Series 6 Measures Blood Oxygen (Sep,20 2020 )

Life is Strange 2 Episode 1 Now Free (Sep,18 2020 )

NVIDIA GeForce 456.38 WHQL Released (Sep,17 2020 )

AMD Releases Radeon Software Adrenalin 20.9.1 (Sep,17 2020 )

Nvidia-Branded CPUs might be a possibility in near future (Sep,16 2020 )

Private data gone public: Razer leaks 100,000+ gamers info (Sep,16 2020 )

Crysis Remastered 8K Tech trailer (Sep,15 2020 )

Star Wars: Squadrons - "Hunted" CG Short (Sep,15 2020 )

LG Wing Boasts Swivel Screen (Sep,14 2020 )

NVIDIA to Acquire Arm for $40 Billion (Sep,14 2020 )

Boundary: Raytracing Benchmark (Sep,14 2020 )

NVIDIA: GeForce RTX 3080 Reviews Delayed (Sep,13 2020 )

What If We Detonated All Nuclear Bombs in Space at Once? (Sep,12 2020 )

WAP Sign Language (Sep,12 2020 )

Android Go Updated to be More Efficient on More Devices (Sep,12 2020 )

Bose Intros QC Earbuds with Advanced ANC (Sep,12 2020 )

NVIDIA GeForce RTX 3080 - Official Unboxing (Sep,10 2020 )

Dune Official Trailer (Sep,10 2020 )

Xbox Series S announced, priced at $299 (Sep,08 2020 )

Android 11 Released (Sep,08 2020 )

i'm thinking of ending things - Official Trailer (Sep,07 2020 )

Novak Djokovic Defaulted From US Open (Sep,06 2020 )

Acer Aspire 5 with AMD Ryzen 7 4700U unboxing and first impressions (Sep,06 2020 )

Honor MagicBook Pro unboxing and first impressions (Sep,06 2020 )

NVIDIA Marbles at Night tech demo (Sep,05 2020 )

Facebook Technologies Stops Sales of Oculus VR Headset in Germany (Sep,04 2020 )

NO TIME TO DIE Trailer (New 2020) James Bond, Daniel Craig (Sep,04 2020 )

The Witcher: Blood Origin May See Jason Momoa Joining the Cast (Sep,04 2020 )

MoveTime Family Watch MT43A (Sep,03 2020 )

NVIDIA RTX 3080 showcased being faster by 55-70% than the RTX (Sep,03 2020 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs