SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

Notifications
    News for you

    Nasty vulnerability shows Galaxy phones can be safer than Google Pixels

    Firmware
    By 

    Last updated: November 10th, 2022 at 15:54 UTC+01:00

    Samsung's security patches usually come with dozens of fixes to vulnerabilities concerning Google's Android OS and Samsung's own software, whether it's One UI or other components that are unique to Galaxy devices. Interestingly enough, the November 2022 security patch has addressed an Android OS security flaw that has plagued Google's Pixel phones for a few good months. But although this fix was mentioned in Samsung's November bulletin, Galaxy device users need not worry about it.

    The vulnerability, labeled CVE-2022-20465, allowed anyone with an extra SIM card to bypass the lock screen of a Pixel 5 or Pixel 6 (at least) and unlock these phones. Indeed, it was a full-fledged lock screen bypass that didn't require any external tools (aside from a regular SIM) or advanced hacking skills.

    As demonstrated by the Pixel owner who found the issue in the video below, anyone with an extra SIM could have unlocked a Pixel phone just by hot-swapping the card, entering the wrong PIN three times, inserting the correct PUK, and then setting up a new PIN.

    This lock screen bypass seemingly was never an issue for Galaxy phones

    Although this massive security flaw appears to have existed for months before Google addressed it on Pixel phones with the November 2022 patch, it seemingly was never a problem for Galaxy phones. Yes, Samsung lists the vulnerability in the November 2022 bulletin, but even before this fix was released, Galaxy phones were seemingly safe from this egregious lock screen bypass flaw.

    Android open-source commits show that the problem was deeply rooted in Android OS and the way the operating system deals with so-called “security screens,” whether they're PIN entry screens, password screens, fingerprint screens, and so on. This appears to be the reason why it took Google a few good months to address the issue for Pixel phones, but it also shows that, sometimes, Samsung's phones are more secure than Google's devices, thanks to the Korean tech giant's own Android skin and proprietary software.

    On the bright side, Samsung devices appear to be safer than Pixels, at the very least in this one instance. Then again, finding this flaw led to a $70,000 reward for the person who helped Google. Had he used a Galaxy device, he probably would've remained unaware of the security flaw and never got that $70,000 reward.

    In any case, if you want to be completely sure that your Galaxy device can't be as easily unlocked through this exploit, you should download and install the November 2022 security patch on your Samsung phone as soon as it is available. So far, it rolled out for several devices, including the Galaxy Z Fold 3 and 4, the Galaxy Z Flip 3 and 4, and the US-unlocked Galaxy Note 20 series, with more to come.

    Firmware GoogleNovember 2022 Security PatchPixel

    You might also like

    Google Pixel 8a is here to take on the Galaxy S23 FE

    Google Pixel 8a is here to take on the Galaxy S23 FE

    Google has launched the Pixel 8a, a trimmed-down version of the Pixel 8 and the most affordable smartphone in the Pixel 8 series. Compared to the Pixel 8, the Pixel 8a has a smaller display, inferior cameras at the front and rear, a smaller battery, and build quality that’s less rugged. Let’s take a look […]

    • By Abid Iqbal Shaik
    • 14 mins ago
    Google Messages rolling out new audio recorder and Voice Moods more widely

    Google Messages rolling out new audio recorder and Voice Moods more widely

    In October 2023, Google started rolling out a redesigned audio recording user interface in the beta version of Google Messages, and in November 2023, the company announced Voice Moods for the messaging platform. Well, Google has now started rolling out the new voice recording panel to the stable version of the app and is making […]

    • By Abid Iqbal Shaik
    • 6 hours ago
    Google Gemini could soon let you play music from YouTube Music

    Google Gemini could soon let you play music from YouTube Music

    Google Gemini supports extensions, and at the moment, Google offers extensions for only first-party applications and services for the chatbot, including those for Google Flights, Google Hotels, Google Maps, Google Workspace, and YouTube. You can enable these extensions to allow the chatbot to access those apps and services and offer better answers to queries. Well, […]

    • By Abid Iqbal Shaik
    • 11 hours ago
    YouTube’s AI-powered Jump Ahead feature now available to more people

    YouTube’s AI-powered Jump Ahead feature now available to more people

    Back in March, Google started testing the ‘Jump Ahead’ button in the YouTube app for Android by making it available to a small number of people. Pressing this button skips the part of the video that most people have skipped. Well, 9To5Google says that the company is now rolling out the Jump Ahead button more […]

    • By Abid Iqbal Shaik
    • 1 day ago
    Android could make data transfer much faster during new phone setup

    Android could make data transfer much faster during new phone setup

    Android has always been great with files and file sharing. One of the most critical times when you need access to files is switching from one device to another. Android has a built-in tool to migrate data from an old phone to a new one, and Samsung has its own data migration tool called Smart […]

    • By Asif Iqbal Shaik
    • 1 day ago
    Google Gemini gets support for more languages on Android

    Google Gemini gets support for more languages on Android

    Gemini is Google's newest AI-powered digital assistant, and it will slowly replace Google Assistant. And for that to happen, Gemini needs support for more languages, access in more countries, and integration with more services. Google is doing just that with a new move. Gemini gets support for more languages and is available in more countries […]

    • By Asif Iqbal Shaik
    • 4 days ago