{"id":401627,"date":"2021-06-14T09:47:21","date_gmt":"2021-06-14T07:47:21","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=401627"},"modified":"2021-06-14T09:48:42","modified_gmt":"2021-06-14T07:48:42","slug":"alarming-security-flaws-found-in-samsung-pre-installed-apps","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/401627-alarming-security-flaws-found-in-samsung-pre-installed-apps.html","title":{"rendered":"Alarming security flaws found in Samsung pre-installed apps"},"content":{"rendered":"<p>An analysis of pre-installed apps on Samsung devices has revealed multiple security bugs which could have been exploited by attackers to spy on users and steal their data.<\/p>\n<p>The vulnerabilities were uncovered by <a href=\"https:\/\/blog.oversecured.com\/Two-weeks-of-securing-Samsung-devices-Part-1\/\" target=\"_blank\" rel=\"noopener\"><strong>mobile security company Oversecured<\/strong><\/a> and first <a href=\"https:\/\/thehackernews.com\/2021\/06\/hackers-can-exploit-samsung-pre.html\" target=\"_blank\" rel=\"noopener\"><strong>reported by Hacker News<\/strong><\/a>.<\/p>\n<p>Oversecured spent two weeks looking for gaps in the security of these apps and discovered seven dangerous vulnerabilities.<\/p>\n<p>The bugs could have resulted in significant privacy violations, with hackers able to access sensitive communication on the users&#8217; devices.<\/p>\n<p>&#8220;The impact of these bugs could have allowed an attacker to access and edit the victim\u2019s contacts, calls, SMS\/MMS, install arbitrary apps with device administrator rights, or read and write arbitrary files on behalf of a system user which could change the device\u2019s settings,&#8221; Oversecured said.<\/p>\n<p>The table below shows the apps in which the vulnerabilities were discovered as well as a description of what kind of attack they allowed.<\/p>\n<div class=\"mybb_table\">\n<div class=\"table-responsive\"><table class=\"table\" border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"7\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" colspan=\"4\" bgcolor=\"#000000\"><span style=\"color: #ffffff;\"><strong>Vulnerabilities in Samsung pre-installed apps<\/strong><\/span><\/td>\n<\/tr>\n<tr>\n<td bgcolor=\"#F5F5F5\" width=\"20%\"><strong>CVE<\/strong><\/td>\n<td bgcolor=\"#F5F5F5\" width=\"20%\"><strong>SVE<\/strong><\/td>\n<td bgcolor=\"#F5F5F5\" width=\"20%\"><strong>Affected app<\/strong><\/td>\n<td bgcolor=\"#F5F5F5\" width=\"40%\"><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25388<\/td>\n<td>SVE-2021-20636<\/td>\n<td>Knox Core<\/td>\n<td>Installation of arbitrary apps and device-wide theft of arbitrary files.<\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25356<\/td>\n<td>SVE-2021-20733<\/td>\n<td>Managed Provisioning<\/td>\n<td>Installing third-party apps and granting them Device Admin permissions.<\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25391<\/td>\n<td>SVE-2021-20500<\/td>\n<td>Secure Folder<\/td>\n<td>Gaining access to arbitrary content providers.<\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25393<\/td>\n<td>SVE-2021-20731<\/td>\n<td>SecSettings<\/td>\n<td>Gaining access to arbitrary content providers leads to read\/write access to arbitrary files as system user (UID 1000).<\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25392<\/td>\n<td>SVE-2021-20690<\/td>\n<td>Samsung DeX System UI<\/td>\n<td>Ability to steal notification policy configuration.<\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25397<\/td>\n<td>SVE-2021-20716<\/td>\n<td>TelephonyUI<\/td>\n<td>(Over-) writing arbitrary files as UID 1001.<\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-25390<\/td>\n<td>SVE-2021-20724<\/td>\n<td>PhotoTable<\/td>\n<td>Intent redirection leads to gaining access to arbitrary content providers.<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>A detailed explanation of how Oversecured was able to exploit each of the vulnerabilities on a testing device can be found on its <strong><a href=\"https:\/\/blog.oversecured.com\/Two-weeks-of-securing-Samsung-devices-Part-1\/\" target=\"_blank\" rel=\"noopener\">website<\/a><\/strong>.<\/p>\n<h3 class=\"my-4\">Samsung rolls out fixes<\/h3>\n<p>Oversecured reported the vulnerabilities to Samsung before revealing them to the public.<\/p>\n<p>Samsung labelled the severity of the vulnerabilities from moderate to high and included fixes for them in its April and May firmware updates.<\/p>\n<p>It also rewarded the company more than $20,500 for disclosing the bugs.<\/p>\n<p>It is recommended that Samsung device owners install the latest firmware updates to prevent falling victim to hackers looking to exploit these bugs.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/internet\/400893-apple-will-not-launch-feature-to-hide-online-identity-in-south-africa-or-china.html\" rel=\"bookmark\">Apple will not launch feature to hide online identity in South Africa or China<\/a><\/h3>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An analysis of pre-installed apps on Samsung devices revealed multiple security bugs which could be exploited by attackers to spy on users and steal their data.<\/p>\n","protected":false},"author":341042,"featured_media":401635,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[15227,199,461,3336,70217,645],"class_list":["post-401627","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cybersecurity","tag-hackers","tag-hacking","tag-mobile-security","tag-oversecured","tag-samsung"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/401627"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341042"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=401627"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/401627\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/401635"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=401627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=401627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=401627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}