Breaking News

ASUS Announces ProArt PA40SU USB4 SSD Enclosure Akasa Introduces 10 Gigabit PCIe Network Card for Desktop, Workstation and Server Upgrades KIOXIA Unveils Value-Oriented QLC-based EG7 Series SSDs for PC OEMs Viltrox Unveils New 35mm and 55mm F1.8 EVO Lenses for Sony FE and Nikon Z Mounts ASRock Adds Support for One Sub-Channel DRAM Module on Intel DDR5 Motherboards

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Finds Security Holes In New Samsung Galaxy S6 Edge

Google Finds Security Holes In New Samsung Galaxy S6 Edge

Smartphones Nov 4,2015 0

Google security researchers put Samsung's Galaxy S6 Edge through its paces over one week and found major flaws in Android code added by the Korean company. Google's Project Zero team discovered and reported 11 high-impact security issues.

The majority of Android devices are not made by Google, but by external companies known as Original Equipment Manufacturers or OEMs which use the Android Open-Source Project (AOSP) as the basis for mobile devices which they manufacture. OEMs introduce additional (and possibly vulnerable) code into Android devices at all privilege levels, and they decide the frequency of the security updates that they provide for their devices to carriers.

Perhaps the most interesting issue found was a directory traversal bug that allows a file to be written as system. There is a process running a system on the device that scans for a zip file in /sdcard/Download/cred.zip and unzips the file. Unfortunately, the API used to unzip the file does not verify the file path, so it can be written in unexpected locations. On the version of the device Google's team tested, this was trivially exploitable using the Dalvik cache using a technique that has been used to exploit other directory traversal bugs, though an SELinux policy that prevents this specific exploitation technique has been pushed to the device since.

Another interesting and easy-to-exploit bug was found in the Samsung Email client by James Forshaw. It is a lack of authentication in one of the client’s intent handlers. An unprivileged application can send a series of intents that causes the user’s emails to be forwarded to another account. It is a very noisy attack, as the forwarded emails show up in the user’s sent folder, but it is still easy access to data that not even a privileged app should be able to access.

A script injection issue was also found in the Samsung email client. This issue allows JavaScript embedded in a message to be executed in the email client. It is somewhat unclear what the worst-case impact of this issue is, but it certainly increases the attack surface of the email client, as it would make JavaScript vulnerabilities in the Android WebView reachable remotely via email.

In addition, there were three issues found in drivers on the device. Buffer overflows were identified in drivers that are accessible by processes that run as media. These could be used by bugs in media processing, such as libstagefright bugs, to escalate to kernel privileges. In addition, a concurrency issue wasleading to memory corruption in a driver that could be used to escalate from any unprivileged application or code execution to kernel.

Five memory corruption issues on the device in Samsung-specific image processing were also identified. Two of these issues occur when an image is opened in Samsung Gallery, but the three others occur during media scanning, which means that an image only needs to be downloaded to trigger these issues. They allow escalation to the privileges of the Samsung Gallery app or the media scanning process.

Google's researchers reported these issues to Samsung soon after they discovered them. They responded recently, stating that they had fixed eight of the issues in their October Maintenance Release, and the remaining issues would be fixed in November.

Tags: SAMSUNG
Previous Post
Lufthansa Signs Google Flights Deal
Next Post
Intel Unveils New IoT Platform

Related Posts

  • Samsung Unveils 115” 4K Smart Signage Display

  • Galaxy AI Is Coming to New Galaxy Watch for More Motivational Health

  • Samsung Introduces Galaxy A55 5G and Galaxy A35 5G

  • Samsung’s New AI PC, Galaxy Book4 Series, Available Globally Beginning February 26

  • Samsung and Google Cloud Join Forces to Bring Generative AI to Samsung Galaxy S24 Series

  • Samsung Galaxy S24 Ultra Creates New Standards of Durability and Visual Clarity With Corning® Gorilla® Armor

  • Samsung announces 2024 Neo QLED, MICRO LED, OLED

  • Samsung Electronics Expands Odyssey Gaming Monitor Lineup With New OLED Models at CES 2024

Latest News

ASUS Announces ProArt PA40SU USB4 SSD Enclosure
PC components

ASUS Announces ProArt PA40SU USB4 SSD Enclosure

Akasa Introduces 10 Gigabit PCIe Network Card for Desktop, Workstation and Server Upgrades
Enterprise & IT

Akasa Introduces 10 Gigabit PCIe Network Card for Desktop, Workstation and Server Upgrades

KIOXIA Unveils Value-Oriented QLC-based EG7 Series SSDs for PC OEMs
Enterprise & IT

KIOXIA Unveils Value-Oriented QLC-based EG7 Series SSDs for PC OEMs

Viltrox Unveils New 35mm and 55mm F1.8 EVO Lenses for Sony FE and Nikon Z Mounts
Cameras

Viltrox Unveils New 35mm and 55mm F1.8 EVO Lenses for Sony FE and Nikon Z Mounts

ASRock Adds Support for One Sub-Channel DRAM Module on Intel DDR5 Motherboards
PC components

ASRock Adds Support for One Sub-Channel DRAM Module on Intel DDR5 Motherboards

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed