BEST OF THE WEB

Google spots vulnerabilities in Exynos chips that could affect Androids

Google is urging Android phone owners, such as those who own Samsung, Pixel, or Vivo phones, to take immediate action to protect themselves from critical vulnerabilities that allow skilled hackers to secretly compromise their devices by dialling a specially crafted number.

This was stated in a warning issued by Google’s Project Zero team after it discovered severe 0-day vulnerabilities in the Samsung Exynos modems used in the Pixel 6 and 7, Samsung phones and wearables, and other devices that necessitate disabling VoLTE and Wi-Fi calling until they are patched. The flaws allow an attacker to remotely compromise a phone at the baseband level without requiring any user interaction, and all the attacker needs is the victim’s phone number.

A variety of Exynos modems are vulnerable due to the vulnerability, which could “allow an attacker to remotely compromise a phone at the baseband level with no user interaction” with little more than a victim’s phone number. The vulnerability affects Android devices that use Samsung’s semiconductor division’s Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5123 chipsets.

The bug is identified as CVE-2023-24033, and three others that have yet to receive a CVE designation allow hackers to execute malicious code, according to Google’s Project Zero vulnerability team. Because the chips are endowed with root-level system privileges to ensure voice calls work reliably, code-execution bugs in the baseband can be especially dangerous.

The team also warns that “with only limited additional research and development,” experienced hackers could exploit the flaw. Google claims that the March Pixel security update will address the issue.

The sources for this piece include an article in ArsTechnica.

IT World Canada Staff
IT World Canada Staffhttp://www.itworldcanada.com/
The online resource for Canadian Information Technology professionals.

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

ITW in your inbox

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

More Best of The Web