[ad_1]
Enlarge / Pictures of the Samsung Galaxy S21, which runs on an Exynos chipset.
SAMSUNG
Google is urging owners of select Android phones to take urgent action to protect themselves against critical vulnerabilities that give skilled hackers the ability to surreptitiously compromise their devices by placing a specially crafted call to their number. It’s unclear whether all of the solicited actions are possible, however, and even if they were, the measures would neutralize the devices most voice calling capabilities.
The vulnerability affects Android devices using the Exynos chipset made by Samsung’s semiconductor division. Vulnerable devices include Pixel 6 and 7, international versions of the Samsung Galaxy S22, various mid-range Samsung phones, Galaxy Watch 4 and 5, and cars with the Exynos Auto T5123 chip. These devices are ONLY vulnerable if they are running the Exynos chipset, which includes the baseband that processes signals for voice calls. The US version of the Galaxy S22 uses a Qualcomm Snapdragon chip.
A tracked bug as CVE-2023-24033 and three others that have yet to receive a CVE designation allow hackers to execute malicious code, Google’s Project Zero vulnerability team reported Thursday. Baseband code execution bugs can be especially critical because the chips are equipped with root-level system privileges to ensure that voice calls work reliably.
“Testing conducted by Project Zero confirms that these four vulnerabilities allow an attacker to remotely compromise a baseband-level phone without any user interaction and only require the attacker to know the victim’s phone number wrote Project Zero’s Tim Willis. “With limited additional R&D, we believe skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.”
Announcement
Earlier this month, Google released a patch for vulnerable Pixel models. Samsung has released a patching update CVE-2023-24033, but it hasn’t been delivered to end users yet. There are no indications that Samsung has released patches for the other three critical vulnerabilities. Until vulnerable devices are patched, they remain vulnerable to attacks that give access to the deepest possible level.
The threat prompted Willis to place this piece of advice at the top of Thursday’s post:
Until security updates are available, users who want to protect against baseband remote code execution vulnerabilities in Samsung’s Exynos chipsets can disable Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings. device. Disabling these settings will eliminate the risk of exploitation of these vulnerabilities.
The problem is that it is not entirely clear whether it is possible to deactivate VoLTE, at least on many models. A screenshot an S22 user posted to Reddit last year shows that the option to turn off VoLTE is greyed out. While that user’s S22 ran a Snapdragon chip, the experience for users of Exynos-based phones is likely the same.
And while it’s possible to turn off VoLTE, doing so in conjunction with turning off Wi-Fi could turn phones into little more than little Android-powered tablets. VoLTE came into widespread use a few years ago, and most carriers in North America have since stopped supporting the older 3G and 2G frequencies.
Samsung representatives said in an email that the company released security patches in March for five of six vulnerabilities that “could potentially impact certain Galaxy devices” and will fix the sixth flaw next month. The email did not respond to questions asking if any of the patches were now available to end users or if VoLTE could be turned off.
Announcement
A Google representative, meanwhile, declined to provide specific steps for executing the advice in Project Zero’s briefing. Readers who find a way are welcome to explain the process (with screenshots, if possible) in the comments section.
Due to the severity of the bugs and ease of exploitation by skilled hackers, Thursday’s post omitted the technical details. On its product security update page, Samsung described CVE-2023-24033 as a “memory corruption processing SDP accept-type attribute”.
“The baseband software does not properly check the SDP-specified accept-type attribute format types, which may lead to denial of service or code execution in the Samsung Baseband modem,” the advisory added. . “Users can disable WiFi calling and VoLTE to mitigate the impact of this vulnerability.”
Short for Service Discovery Protocol layer, SDP allows the discovery of services available from other devices via Bluetooth. In addition to discovery, SDP allows applications to determine the technical characteristics of these services. SDP uses a request/response model for device communication.
The threat is serious, but again, it only applies to people using an Exynos version of one of the affected models. And once again, Google released a patch earlier this month for Pixel users.
Until Samsung or Google say more, users of devices that remain vulnerable should (1) install all available security updates by paying attention to a CVE-2023-24033 patch, (2) turn off Wi-Fi calling, and (3) explore their specific model’s settings menu to see if VoLTE can be turned off. This post will be updated if any of the companies respond with more useful information.
|
Sources 2/ https://arstechnica.com/information-technology/2023/03/critical-vulnerabilities-allow-some-android-phones-to-be-hacked/ The mention sources can contact us to remove/changing this article |
[ad_2]