MASSIVE Samsung Galaxy deals during Discover Samsung!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

[Updated] Samsung keeps ignoring a huge security flaw in millions of Galaxy phones

General
By 

Last updated: April 4th, 2023 at 13:26 UTC+02:00

A massive Mali GPU security flaw that virtually affects millions of Samsung phones running on Exynos chipsets was confirmed last year in November. Since then, this Mali vulnerability became a part of a chain that hackers successfully exploited to lead unsuspecting Samsung Internet users to malicious websites. And although that particular exploit chain was broken, the Mali security flaw uncovered last year continues to affect almost every Samsung device powered by Exynos, save for the Galaxy S22 and its Xclipse 920 GPU.

Google’s Threat Analysis Group (TAG) revealed the exploit chain earlier today. In December 2022, TAG discovered this exploit chain that relies on multiple 0-day and n-day vulnerabilities and targets the Chrome and Samsung Internet browsers.

More specifically, two vulnerabilities in this chain concern Chrome. And since Samsung Internet Browser uses Chromium, the app was used as an attack vector in conjunction with the Mali GPU kernel driver vulnerability reported last year. This Mali exploit grants attackers system access.

Through this chain of exploits, hackers would send one-time links via SMS to Samsung Galaxy devices located in the UAE (United Arab Emirates). The links would redirect unsuspecting users to a page that would deliver “a fully featured Android spyware suite written in C++ that includes libraries for decrypting and capturing data from various chat and browser applications.”

The chain was broken. But Samsung keeps ignoring the Mali GPU issue

What’s the current situation? Well, Google fixed those two Chrome vulnerabilities mentioned above and patched its own Pixel phones at the beginning of 2023. Samsung also fixed its Samsung Internet browser in December 2022. The Korean tech giant addressed the two flaws related to Chromium (CVE-2022-4262 and CVE-2022-3038) through an Internet browser app update after version 19.0.6.

Samsung broke the exploit chain that was leveraging its Chromium-based Internet app and the Mali kernel vulnerability in December, and it appears that the attacks on users in the UAE have stopped. However, one glaring issue remains.

The exploit chain Google detailed today was addressed thanks to Samsung Internet browser updates in December. But one link in the chain, consisting of the massive Mali security vulnerability (CVE-2022-22706), remains unpatched on Samsung devices equipped with Exynos chipsets and Mali GPUs. That is, despite the fact that Mali already provided a fix for its kernel driver exploit as early as January 2022.

Until Samsung mends this issue through a security firmware patch containing the Mali fix, it appears that the majority of Galaxy devices featuring Exynos SoCs remain vulnerable to the Mali GPU kernel driver exploit.

Update: Samsung reached out to us with the following statement “Samsung takes the security of its products very seriously. We have already taken necessary steps to prevent these potential exploit chains by issuing patches for the Samsung Internet app in December 2022. December’s updates to the Samsung Internet app disable entry points for the remaining vulnerabilities and ensure devices are protected.

We are actively collaborating with our partners to release patches for the remaining vulnerabilities as early as possible, starting April, and recommend all users keep their devices updated with the latest software to ensure the highest level of protection possible.”

FirmwareGeneralPhone ExynosSamsung Electronics
Load comments

You might also like

Apple may beat Samsung to the punch and unveil its mixed-reality headset in June

Apple may beat Samsung to the punch and unveil its mixed-reality headset in June

Apple and Samsung are about to engage in a heated rivalry across a new market segment, as both companies are developing mixed-reality (XR) headsets. This time, however, Apple might take the emerging XR market by storm before Samsung does, and a new report reveals that the Cupertino giant has thrown everything at has at its […]

  • By Mihai Matei
  • 32 mins ago
Snapdragon 8 Gen 2’s faster version is no longer exclusive to Samsung

Snapdragon 8 Gen 2’s faster version is no longer exclusive to Samsung

For the first time in its history, Samsung used a Snapdragon processor in all its Galaxy S series (Galaxy S23) phones worldwide. Experts and users praised the company a lot for this step, as the chip brought incredible battery life and performance. The Snapdragon 8 Gen 2 For Galaxy, a chip that has been exclusive […]

  • By Asif Iqbal Shaik
  • 2 hours ago
Samsung-developed Level 4 autonomous car system passed a 200km test run

Samsung-developed Level 4 autonomous car system passed a 200km test run

Samsung is reportedly one step closer to developing a self-driving system almost as good, or as good, as Level 4 autonomous driving. Reportedly, SAIT (Samsung Advanced Institute of Technology) successfully ran and concluded a “driver-free” test from Suwon to Gangneung in South Korea. A report from the local media says that Samsung’s R&D team created […]

  • By Mihai Matei
  • 3 days ago
Galaxy S23 and A-series secure 1st place for Samsung in the Middle East

Galaxy S23 and A-series secure 1st place for Samsung in the Middle East

Smartphone shipments in the Middle East (excluding Turkey) have declined year-on-year, but despite this, expectations were much lower, and the market performed significantly better than anticipated. Samsung led the Middle Eastern smartphone market in Q1 2023 and was followed by Apple. Market watchers were expecting the Middle Eastern market to record an annual decline of […]

  • By Mihai Matei
  • 3 days ago
Samsung and Apple want to manufacture more devices in India

Samsung and Apple want to manufacture more devices in India

In recent years, India has become one of Samsung’s main manufacturing hubs for smartphones and phone components. Now, Samsung is reportedly preparing to expand its production in India even more, as the country is launching a $2.1 billion plan to incentivize local production of more consumer devices. And according to reports, Apple has similar goals […]

  • By Mihai Matei
  • 3 days ago
LG Display could finally turn a profit next year thanks to Samsung

LG Display could finally turn a profit next year thanks to Samsung

In an unexpected turn of events, Samsung Electronics struck a deal with LG Display to buy some of its W-OLED TV panels. Samsung will need a whopping 2 million panels from LG Display in the first year, and then that number is only expected to rise. And as expected, this deal will help both parties. […]

  • By Mihai Matei
  • 4 days ago