DEAL Galaxy S24 FE, Galaxy Watch 7. Subscribe today and be the first to learn about One 7 beta!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Samsung devices vulnerable to malware apps due to security leak

Phone
By 

Last updated: December 2nd, 2022 at 14:32 UTC+01:00

Millions of Android devices, including Samsung, appear to have been left vulnerable by a major security leak. This isn't as much a vulnerability as it is an actual leak of a critical component used by device manufacturers who rely on Android OS.

More specifically, Android OEMs, including LG, Samsung, and others, have had their platform signing keys leaked. A signing key ensures that the version of Android on a device is legitimate. In addition, the signing key can be used by individual apps, meaning that Android will trust any app that shares the same signing key as the operating system. (via @maldr0id / 9to5Google)

In theory, this can allow a malicious party to attach malware to a trusted app and go unnoticed. It wouldn't matter if a new app version contains malware. As long as the app is signed using the same key as the OS, it would be considered a trusted update, regardless of whether it came from the Galaxy Store, the Play Store, or other sources. That is, in theory. Google claims that no such vulnerable apps have made it onto the Play Store, which is good news.

Samsung already took measures to minimize risks

Aside from Samsung, other mobile brands affected by this security leak are LG, MediaTek, szroco, Revoview, and there may be others.

The issue was originally reported in May 2022, and thankfully, Google says that Samsung (and other manufacturers) have “taken remediation measures to minimize the user impact.” The statement is a bit fuzzy, and it's unclear which apps are still vulnerable to this security issue or to what extent. But measures were set in place to minimize the risk of getting malware. And thankfully, Google also said that the exploit hasn't been found in any apps available through the Play Store, and ensured that Play Protect offers a layer of security against these vulnerabilities.

In any case, it seems like the best way to avoid problems caused by this security leak is to not sideload apps from third-party websites for a while.

PhoneTablet Samsung Electronics
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Samsung CEO wants employees to make desperate efforts to improve products

Samsung CEO wants employees to make desperate efforts to improve products

Samsung is in a bit of a crisis right now. While the company has been the world's biggest memory chip maker for decades, it seems to have lost its footing in high-end memory chips (HBM) used in AI accelerators and GPUs. In times like these, Samsung CEO urged employees to focus on attaining technology leadership. […]

  • By Asif Iqbal Shaik
  • 7 hours ago
Samsung’s profit jumps 72.8% in Q3 2024 despite chip struggles

Samsung’s profit jumps 72.8% in Q3 2024 despite chip struggles

Earlier today, Samsung announced its earnings for the third quarter of 2024. While the company's profits beat market expectations, its struggles in the memory chip market remain. The South Korean firm reported a consolidated revenue of KRW 79.1 trillion ($57.34 billion) and an operating profit of KRW 10.1 trillion ($7.3 billion). Samsung's net profit in […]

  • By Asif Iqbal Shaik
  • 1 day ago
Samsung’s device repair network welcomes 300+ more locations

Samsung’s device repair network welcomes 300+ more locations

Samsung's customer care network is expanding. The company announced today that its partnership with Cell Phone Repair (CPR) by Assurant, an Independent Service Provider (ISP) within Samsung's repair network, is opening more than 300 new service locations before the end of 2024. At the beginning of the year, CPR had roughly 100 locations certified by […]

  • By Mihai Matei
  • 3 days ago
Samsung goes all nostalgic for the ‘glorious Y2K era’

Samsung goes all nostalgic for the ‘glorious Y2K era’

Samsung has become nostalgic for the year 2000 and has partnered with two designers to create new accessories inspired by popular trends of the era. This new collection of accessories, designed for the Galaxy Z Flip 6 and the Galaxy Buds 3, recalls “the simpler and more fun years of our youth,” when the Internet […]

  • By Mihai Matei
  • 1 week ago
Clever trick from Samsung might fix moisture detection warnings

Clever trick from Samsung might fix moisture detection warnings

Samsung Galaxy phones and tablets boast a high level of water resistance, but the USB ports are not covered, and as everyone knows, water and electronic circuits don't go well together. To avoid water damage and keep water resistance without resorting to USB port covers, Samsung developed a clever software component that automatically detects moisture […]

  • By Mihai Matei
  • 2 weeks ago
New insight tells different story of Samsung-Apple rivalry in Q3

New insight tells different story of Samsung-Apple rivalry in Q3

Yesterday, we covered some market data for the global smartphone segment in Q3 and reported that, according to those numbers, Samsung and Apple held roughly the same market share in the third quarter of 2024. However, different analysts use different methodologies, and today, fresh insight from Counterpoint Research paints a new picture. While Canalys data […]

  • By Mihai Matei
  • 2 weeks ago