Samsung Galaxy phones found a serious security vulnerability that took 6 years to fix

Publisher:学海飘香Latest update time:2020-05-09 Source: 快科技Keywords:Samsung Reading articles on mobile phones Scan QR code
Read articles on your mobile phone anytime, anywhere

       According to media reports, Samsung released monthly security updates and smartphones sold since the end of 2014 have a "perfect 10" critical security vulnerability that can enable arbitrary remote code once exploited.

  According to reports, Samsung added support for the Qmage image format (.qmg) to all its mobile phones at the end of 2014, and Samsung's customized Android system has vulnerabilities in handling Qmage.

  Mateusz Jurczyk, a security researcher at Google's Project Zero, discovered a way to exploit Skia (Android's graphics library) to process Qmage images sent to the device.

  Jurczyk said the Qmage bug can be exploited with zero clicks, without user action, by repeatedly sending MMS messages to a Samsung device, with each message attempting to guess where the Skia library is located in the Android phone's memory, which is necessary to bypass Android's ASLR (Address Space Layout Randomization) protection.

  The attacker typically takes around 100 minutes to send 50 to 300 MMS messages to probe and bypass ASLR. Once the Skia library is located in memory, the last MMS message delivers the actual Qmage payload, which then executes the attacker's code on the device.

  While this attack may seem intensive, it can also be modified to execute without alerting the user. Samsung fixed this in a May security update.


Keywords:Samsung Reference address:Samsung Galaxy phones found a serious security vulnerability that took 6 years to fix

Previous article:Breaking news: realme X2 Pro supports unlocking BL
Next article:Huawei applies for utility model patent: a vibration motor and electronic equipment patent

Latest Mobile phone portable Articles
Change More Related Popular Components

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号