Best buy guide: Galaxy Watch 6 or Galaxy S24+. Woo-hoo join SamMobile on WhatsApp or Telegram!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

Notifications
    News for you

    [Updated] Samsung keeps ignoring a huge security flaw in millions of Galaxy phones

    General
    By 

    Last updated: April 4th, 2023 at 13:26 UTC+02:00

    A massive Mali GPU security flaw that virtually affects millions of Samsung phones running on Exynos chipsets was confirmed last year in November. Since then, this Mali vulnerability became a part of a chain that hackers successfully exploited to lead unsuspecting Samsung Internet users to malicious websites. And although that particular exploit chain was broken, the Mali security flaw uncovered last year continues to affect almost every Samsung device powered by Exynos, save for the Galaxy S22 and its Xclipse 920 GPU.

    Google's Threat Analysis Group (TAG) revealed the exploit chain earlier today. In December 2022, TAG discovered this exploit chain that relies on multiple 0-day and n-day vulnerabilities and targets the Chrome and Samsung Internet browsers.

    More specifically, two vulnerabilities in this chain concern Chrome. And since Samsung Internet Browser uses Chromium, the app was used as an attack vector in conjunction with the Mali GPU kernel driver vulnerability reported last year. This Mali exploit grants attackers system access.

    Through this chain of exploits, hackers would send one-time links via SMS to Samsung Galaxy devices located in the UAE (United Arab Emirates). The links would redirect unsuspecting users to a page that would deliver “a fully featured Android spyware suite written in C++ that includes libraries for decrypting and capturing data from various chat and browser applications.”

    The chain was broken. But Samsung keeps ignoring the Mali GPU issue

    What's the current situation? Well, Google fixed those two Chrome vulnerabilities mentioned above and patched its own Pixel phones at the beginning of 2023. Samsung also fixed its Samsung Internet browser in December 2022. The Korean tech giant addressed the two flaws related to Chromium (CVE-2022-4262 and CVE-2022-3038) through an Internet browser app update after version 19.0.6.

    Samsung broke the exploit chain that was leveraging its Chromium-based Internet app and the Mali kernel vulnerability in December, and it appears that the attacks on users in the UAE have stopped. However, one glaring issue remains.

    The exploit chain Google detailed today was addressed thanks to Samsung Internet browser updates in December. But one link in the chain, consisting of the massive Mali security vulnerability (CVE-2022-22706), remains unpatched on Samsung devices equipped with Exynos chipsets and Mali GPUs. That is, despite the fact that Mali already provided a fix for its kernel driver exploit as early as January 2022.

    Until Samsung mends this issue through a security firmware patch containing the Mali fix, it appears that the majority of Galaxy devices featuring Exynos SoCs remain vulnerable to the Mali GPU kernel driver exploit.

    Update: Samsung reached out to us with the following statement “Samsung takes the security of its products very seriously. We have already taken necessary steps to prevent these potential exploit chains by issuing patches for the Samsung Internet app in December 2022. December's updates to the Samsung Internet app disable entry points for the remaining vulnerabilities and ensure devices are protected.

    We are actively collaborating with our partners to release patches for the remaining vulnerabilities as early as possible, starting April, and recommend all users keep their devices updated with the latest software to ensure the highest level of protection possible.”

    FirmwareGeneralPhone ExynosSamsung Electronics

    You might also like

    Top-level visits underway as Samsung seeks turnaround in China

    Top-level visits underway as Samsung seeks turnaround in China

    China is an important market and while Samsung once enjoyed a considerable share in the country's smartphone market, it has since fallen to 0%. The company needs to do a lot more than just launch basic phones to revive its fortunes in the lucrative market. Samsung has set up a dedicated team to pursue a […]

    • By Adnan Farooqui
    • 2 days ago
    Samsung and Google tease new AI features

    Samsung and Google tease new AI features

    Samsung and Google have started teasing new AI (Artificial Intelligence) features developed through a partnership that's never been stronger. In a recent social media post on X, both Samsung Mobile and Google's Rick Osterloh confirmed that the two companies are continuing to work together to develop new exciting features. According to these recent teasers, Google's […]

    • By Mihai Matei
    • 3 days ago
    Samsung LATAM wants to recycle nearly 15,000 tons of e-waste in 2024

    Samsung LATAM wants to recycle nearly 15,000 tons of e-waste in 2024

    Samsung will extend its recycling and waste collection efforts to three more Latin American countries. During Earth Day earlier this week, the company announced that it will run its waste collection program in 13 countries instead of 10. Through its extended efforts, Samsung's new goal for 2024 is to collect a minimum of 14,183 tons […]

    • By Mihai Matei
    • 3 days ago
    Galaxy Z Flip smartphones may eventually get a zoom camera

    Galaxy Z Flip smartphones may eventually get a zoom camera

    One thing the Galaxy Z Flip series lacks is a telephoto camera. All the models released so far only feature wide and ultra-wide lenses, but new evidence has emerged to suggest that Samsung might eventually add a third sensor to the back of its future Galaxy Z Flip phones. A Samsung patent unearthed by GalaxyClub […]

    • By Mihai Matei
    • 3 days ago
    Samsung outfits Amazon’s latest film studio with cutting-edge LEDs

    Samsung outfits Amazon’s latest film studio with cutting-edge LEDs

    Samsung is showcasing its display technology prowess through a new collaboration with Amazon that revolves around its latest addition to its entertainment business portfolio: Culver Post. The latter is a state-of-the-art theatrical post-production studio located in Los Angeles. Samsung says it has partnered with 424 Post and Harbor to provide advanced display technologies for Amazon's […]

    • By Mihai Matei
    • 4 days ago
    Samsung Rewards loyalty program is now available in Canada

    Samsung Rewards loyalty program is now available in Canada

    Prospective Samsung customers in Canada now have one extra reason to use a Samsung Account when they purchase new products. The Korean tech giant announced it is bringing the Samsung Rewards program to Canada, allowing customers to earn points and exclusive benefits. Samsung Rewards is a loyalty program that lets customers accumulate points whenever they […]

    • By Mihai Matei
    • 4 days ago