SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Security researcher says that Tizen is a hacker’s dream, has 40 unknown zero-day vulnerabilities

Phone
By 

Last updated: April 3rd, 2017 at 23:33 UTC+02:00

Samsung plans to reduce its reliance on Android by launching Tizen-powered smartphones, smartwatches, fitness trackers, and TVs. However, the company's Android alternative seems to have serious security related issues. A security researcher has found 40 zero-day vulnerabilities in Tizen, making millions of smartphones, smartwatches, and TVs vulnerable to hacking.

After it had came to notice last month that CIA could hack Tizen-powered Samsung smart TVs, an Israeli security researcher Amihai Neiderman managed to find 40 zero-day vulnerabilities in Tizen's code base. These vulnerabilities would allow someone to remotely hack a Tizen-powered device. Moreover, unlike the CIA hack, these newfound vulnerabilities (also known as remote code execution) do not need a device's physical address.

“It may be the worst code I've ever seen. Everything you can do wrong there, they do it. You can see that nobody with any understanding of security looked at this code or wrote it. It's like taking an undergraduate and letting him program your software.”

Of all the vulnerabilities, Neiderman found one particular design flaw inside the Tizen store, which is said to be critical. According to Neiderman, this vulnerability allowed him to hijack the software to deliver malicious code into his Samsung TV. Since the Tizen Store has the highest privileges, it can be used by a hacker as a Holy Grail for abuse.

Amihai Neiderman, who heads research at Equus Software, first started studying Tizen's security issues when he purchased a Tizen-powered Samsung smart TV. Once he found out how badly written his TV's code is, he bought a bunch of smartphones to test Tizen. He says that a lot of Tizen's code base is old and borrowed from Bada OS, but most of the vulnerabilities he found were from the code that was written within the last two years.

“You can see that they took all this code and tried to push it into Tizen,” Neiderman says.

Samsung says that it is now in contact with Neiderman to solve all the vulnerabilities and security issues in Tizen's code. He also suggests that Samsung should reconsider deploying Tizen in phones before doing a major overhaul of the code. 

 

Source PhoneTVWatch Tizen
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Luxury brand Loewe adopts Samsung’s Tizen OS for its next TV

Luxury brand Loewe adopts Samsung’s Tizen OS for its next TV

Samsung Electronics and European premium TV manufacturer Loewe have found common ground through the Tizen Licensing Program. Today, Samsung announced that Loewe's upcoming premium TV will be infused with its DNA and be powered by Tizen OS. Loewe released its latest premium TV, called ‘stellar,' today, July 15. This is the first time for the […]

  • By Mihai Matei
  • 2 weeks ago
Tidal music streaming app is going away from Samsung TVs

Tidal music streaming app is going away from Samsung TVs

If you have a Samsung TV and stream music from Tidal, we have some bad news for you. Tidal has announced that it is retiring its music streaming app for Samsung's TVs. This is a general direction that Tidal has taken over the past few weeks, and it has already removed its app from Amazon's […]

  • By Asif Iqbal Shaik
  • 1 month ago
Tizen update adds new features and apps to older Bespoke fridges

Tizen update adds new features and apps to older Bespoke fridges

Samsung's Bespoke Family Hub refrigerators got smarter in 2024 thanks to improvements to the AI Vision Inside system, which learned to recognize more than 30 food items. However, there's more to the 2024 Bespoke Family Hub fridges than AI Vision Inside, and some of those other quality-of-life Tizen features are now coming to older models […]

  • By Mihai Matei
  • 1 month ago
Tizen update for Samsung TVs brings big changes to Wi-Fi sound

Tizen update for Samsung TVs brings big changes to Wi-Fi sound

Samsung is rolling out a new update for its smart TV lineup, pushing Tizen OS to version 1420. It is the third major firmware update we've got over the past few months, and similar to the previous one released in May, it deals with the audio experience rather than the visual side. The good news […]

  • By Mihai Matei
  • 1 month ago
Samsung to stop supporting its Tizen smartwatches from next year

Samsung to stop supporting its Tizen smartwatches from next year

There was a time when Samsung's smartwatches used to run on its Tizen operating system. The company later decided to switch over to Wear OS with the Galaxy Watch 4 series, and has remained on the Android-powered platform ever since. If it wasn't clear that Samsung is never going to release another Tizen smartwatch, the […]

  • By Adnan Farooqui
  • 2 months ago
Try this trick if you can’t reboot your Samsung TV

Try this trick if you can’t reboot your Samsung TV

Although Tizen is one of the more stable smart TV operating systems on the market, you might sometimes find yourself in a situation where you need to fully power-cycle your Samsung TV — for example, if you get a Netflix connection error. However, in some cases, you might have trouble rebooting your Samsung TV even […]

  • By Mihai Matei
  • 2 months ago