DEAL Galaxy S24 FE, Galaxy Watch 7. Subscribe today and be the first to learn about One 7 beta!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Security researcher says that Tizen is a hacker’s dream, has 40 unknown zero-day vulnerabilities

Phone
By 

Last updated: April 3rd, 2017 at 23:33 UTC+02:00

Samsung plans to reduce its reliance on Android by launching Tizen-powered smartphones, smartwatches, fitness trackers, and TVs. However, the company's Android alternative seems to have serious security related issues. A security researcher has found 40 zero-day vulnerabilities in Tizen, making millions of smartphones, smartwatches, and TVs vulnerable to hacking.

After it had came to notice last month that CIA could hack Tizen-powered Samsung smart TVs, an Israeli security researcher Amihai Neiderman managed to find 40 zero-day vulnerabilities in Tizen's code base. These vulnerabilities would allow someone to remotely hack a Tizen-powered device. Moreover, unlike the CIA hack, these newfound vulnerabilities (also known as remote code execution) do not need a device's physical address.

“It may be the worst code I've ever seen. Everything you can do wrong there, they do it. You can see that nobody with any understanding of security looked at this code or wrote it. It's like taking an undergraduate and letting him program your software.”

Of all the vulnerabilities, Neiderman found one particular design flaw inside the Tizen store, which is said to be critical. According to Neiderman, this vulnerability allowed him to hijack the software to deliver malicious code into his Samsung TV. Since the Tizen Store has the highest privileges, it can be used by a hacker as a Holy Grail for abuse.

Amihai Neiderman, who heads research at Equus Software, first started studying Tizen's security issues when he purchased a Tizen-powered Samsung smart TV. Once he found out how badly written his TV's code is, he bought a bunch of smartphones to test Tizen. He says that a lot of Tizen's code base is old and borrowed from Bada OS, but most of the vulnerabilities he found were from the code that was written within the last two years.

“You can see that they took all this code and tried to push it into Tizen,” Neiderman says.

Samsung says that it is now in contact with Neiderman to solve all the vulnerabilities and security issues in Tizen's code. He also suggests that Samsung should reconsider deploying Tizen in phones before doing a major overhaul of the code. 

 

Source PhoneTVWatch Tizen
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Samsung to unveil One UI 7.0 at SDC Korea next month?

Samsung to unveil One UI 7.0 at SDC Korea next month?

Earlier this month, the Samsung Developer Conference (SDC) 2024 was held in the US, but the company didn't unveil the design and features of One UI 7.0 at the event. Instead, it said it would open the One UI 7.0 Beta Program before the end of this year. Now, it appears that it could open […]

  • By Asif Iqbal Shaik
  • 17 hours ago
Samsung brings Generative AI wallpapers to its 2024 TVs

Samsung brings Generative AI wallpapers to its 2024 TVs

Samsung has announced it is bringing Generative AI wallpapers to its most recent high-end TVs. This feature debuted with the Galaxy S24 series earlier this year and then expanded to older high-end smartphones. The company announced it will bring the feature to its TVs at the Samsung Developer Conference (SDC) 2024. Samsung's TVs launched in […]

  • By Asif Iqbal Shaik
  • 7 days ago
Samsung starts rolling out One UI update to its TVs!

Samsung starts rolling out One UI update to its TVs!

A few days ago, during the Samsung Developer Conference (SDC) 2024, Samsung announced it would bring One UI to its TVs. The company has now fulfilled its promise. Starting today, Samsung has started rolling out the One UI update to its smart TVs. We are surprised to see the update reach TVs so quickly after […]

  • By Asif Iqbal Shaik
  • 2 weeks ago
Samsung TVs get Generative AI features like AI Cast and ChatGPT

Samsung TVs get Generative AI features like AI Cast and ChatGPT

AI, improved security, and an expanded device and software ecosystem were the widespread themes at this year's Samsung Developer Conference. For smart TV users, Samsung announced a wide range of Bixby upgrades at SDC24, and one of the best AI-centric upcoming tools is called Samsung AI Cast. With Samsung AI Cast, Generative AI is coming […]

  • By Mihai Matei
  • 4 weeks ago
An overview of what Samsung is announcing at its developer conference

An overview of what Samsung is announcing at its developer conference

We are in San Jose for the Samsung Developer Conference (SDC24), where the company offered an overview of its software-related plans for the future. Jong-Hee Han, Vice Chairman, CEO, and Head of the Samsung Device eXperience (DX) Division, talked about the company's strategy. An even greater focus on AI experiences Unsurprisingly, Samsung's current vision involves […]

  • By Mihai Matei
  • 4 weeks ago
Samsung unveils an AI shot-in-the-arm for Tizen at SDC 2024

Samsung unveils an AI shot-in-the-arm for Tizen at SDC 2024

The Samsung Developers Conference 2024 is happening today in San Jose, California, and we’re in attendance to check out all of the new software related advancements that the company is unveiling at the event. It was expected that Tizen will get some love as well, and it most certainly has, in perhaps the most unsurprising […]

  • By Adnan Farooqui
  • 4 weeks ago