Best buy guide: Galaxy Watch 6 or Galaxy S24+. Woo-hoo join SamMobile on WhatsApp or Telegram!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

Notifications
    News for you

    [Updated] Samsung keeps ignoring a huge security flaw in millions of Galaxy phones

    General
    By 

    Last updated: April 4th, 2023 at 13:26 UTC+02:00

    A massive Mali GPU security flaw that virtually affects millions of Samsung phones running on Exynos chipsets was confirmed last year in November. Since then, this Mali vulnerability became a part of a chain that hackers successfully exploited to lead unsuspecting Samsung Internet users to malicious websites. And although that particular exploit chain was broken, the Mali security flaw uncovered last year continues to affect almost every Samsung device powered by Exynos, save for the Galaxy S22 and its Xclipse 920 GPU.

    Google's Threat Analysis Group (TAG) revealed the exploit chain earlier today. In December 2022, TAG discovered this exploit chain that relies on multiple 0-day and n-day vulnerabilities and targets the Chrome and Samsung Internet browsers.

    More specifically, two vulnerabilities in this chain concern Chrome. And since Samsung Internet Browser uses Chromium, the app was used as an attack vector in conjunction with the Mali GPU kernel driver vulnerability reported last year. This Mali exploit grants attackers system access.

    Through this chain of exploits, hackers would send one-time links via SMS to Samsung Galaxy devices located in the UAE (United Arab Emirates). The links would redirect unsuspecting users to a page that would deliver “a fully featured Android spyware suite written in C++ that includes libraries for decrypting and capturing data from various chat and browser applications.”

    The chain was broken. But Samsung keeps ignoring the Mali GPU issue

    What's the current situation? Well, Google fixed those two Chrome vulnerabilities mentioned above and patched its own Pixel phones at the beginning of 2023. Samsung also fixed its Samsung Internet browser in December 2022. The Korean tech giant addressed the two flaws related to Chromium (CVE-2022-4262 and CVE-2022-3038) through an Internet browser app update after version 19.0.6.

    Samsung broke the exploit chain that was leveraging its Chromium-based Internet app and the Mali kernel vulnerability in December, and it appears that the attacks on users in the UAE have stopped. However, one glaring issue remains.

    The exploit chain Google detailed today was addressed thanks to Samsung Internet browser updates in December. But one link in the chain, consisting of the massive Mali security vulnerability (CVE-2022-22706), remains unpatched on Samsung devices equipped with Exynos chipsets and Mali GPUs. That is, despite the fact that Mali already provided a fix for its kernel driver exploit as early as January 2022.

    Until Samsung mends this issue through a security firmware patch containing the Mali fix, it appears that the majority of Galaxy devices featuring Exynos SoCs remain vulnerable to the Mali GPU kernel driver exploit.

    Update: Samsung reached out to us with the following statement “Samsung takes the security of its products very seriously. We have already taken necessary steps to prevent these potential exploit chains by issuing patches for the Samsung Internet app in December 2022. December's updates to the Samsung Internet app disable entry points for the remaining vulnerabilities and ensure devices are protected.

    We are actively collaborating with our partners to release patches for the remaining vulnerabilities as early as possible, starting April, and recommend all users keep their devices updated with the latest software to ensure the highest level of protection possible.”

    FirmwareGeneralPhone ExynosSamsung Electronics

    You might also like

    iPhone feels dated as Apple’s sales drop and Samsung rises

    iPhone feels dated as Apple’s sales drop and Samsung rises

    Samsung doomsayers on social media have criticized the Korean tech giant and mobile head TM Roh for the so-called stagnant flagship smartphone design in recent years. If you were to listen to these experts, you would've thought Samsung's end was near. However, two years have passed since Samsung changed its pace and the end is […]

    • By Danny Dorresteijn
    • 1 day ago
    Samsung ramping up efforts to cash in on the AI boom

    Samsung ramping up efforts to cash in on the AI boom

    The AI boom presents a significant business opportunity for Samsung, one of the world's leading suppliers of memory products, as the demand for high-performance memory solutions skyrockets due to their use in artificial intelligence semiconductors. Samsung has already secured billions of dollars worth of deals to supply HBM3E advanced memory chips to companies like NVIDIA […]

    • By Adnan Farooqui
    • 3 days ago
    Samsung profit jumps 933% to $4.8 billion in Q1 2024, beating estimates

    Samsung profit jumps 933% to $4.8 billion in Q1 2024, beating estimates

    Samsung has revealed its financial results for the first quarter of this year, a few weeks after revealing revenue estimates. The company revealed that its revenue rose 13% compared to Q1 2023, while its profit skyrocketed nearly 10x (933%) compared to the year earlier. Samsung's profit jumps nearly 10x in Q1 2024, thanks to strong […]

    • By Asif Iqbal Shaik
    • 4 days ago
    Top-level visits underway as Samsung seeks turnaround in China

    Top-level visits underway as Samsung seeks turnaround in China

    China is an important market and while Samsung once enjoyed a considerable share in the country's smartphone market, it has since fallen to 0%. The company needs to do a lot more than just launch basic phones to revive its fortunes in the lucrative market. Samsung has set up a dedicated team to pursue a […]

    • By Adnan Farooqui
    • 1 week ago
    Samsung and Google tease new AI features

    Samsung and Google tease new AI features

    Samsung and Google have started teasing new AI (Artificial Intelligence) features developed through a partnership that's never been stronger. In a recent social media post on X, both Samsung Mobile and Google's Rick Osterloh confirmed that the two companies are continuing to work together to develop new exciting features. According to these recent teasers, Google's […]

    • By Mihai Matei
    • 1 week ago
    Samsung LATAM wants to recycle nearly 15,000 tons of e-waste in 2024

    Samsung LATAM wants to recycle nearly 15,000 tons of e-waste in 2024

    Samsung will extend its recycling and waste collection efforts to three more Latin American countries. During Earth Day earlier this week, the company announced that it will run its waste collection program in 13 countries instead of 10. Through its extended efforts, Samsung's new goal for 2024 is to collect a minimum of 14,183 tons […]

    • By Mihai Matei
    • 1 week ago