DEAL Galaxy S24 FE, Galaxy Watch 7. Subscribe today and be the first to learn about One 7 beta!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

[Updated] Samsung keeps ignoring a huge security flaw in millions of Galaxy phones

General
By 

Last updated: April 4th, 2023 at 13:26 UTC+02:00

A massive Mali GPU security flaw that virtually affects millions of Samsung phones running on Exynos chipsets was confirmed last year in November. Since then, this Mali vulnerability became a part of a chain that hackers successfully exploited to lead unsuspecting Samsung Internet users to malicious websites. And although that particular exploit chain was broken, the Mali security flaw uncovered last year continues to affect almost every Samsung device powered by Exynos, save for the Galaxy S22 and its Xclipse 920 GPU.

Google's Threat Analysis Group (TAG) revealed the exploit chain earlier today. In December 2022, TAG discovered this exploit chain that relies on multiple 0-day and n-day vulnerabilities and targets the Chrome and Samsung Internet browsers.

More specifically, two vulnerabilities in this chain concern Chrome. And since Samsung Internet Browser uses Chromium, the app was used as an attack vector in conjunction with the Mali GPU kernel driver vulnerability reported last year. This Mali exploit grants attackers system access.

Through this chain of exploits, hackers would send one-time links via SMS to Samsung Galaxy devices located in the UAE (United Arab Emirates). The links would redirect unsuspecting users to a page that would deliver “a fully featured Android spyware suite written in C++ that includes libraries for decrypting and capturing data from various chat and browser applications.”

The chain was broken. But Samsung keeps ignoring the Mali GPU issue

What's the current situation? Well, Google fixed those two Chrome vulnerabilities mentioned above and patched its own Pixel phones at the beginning of 2023. Samsung also fixed its Samsung Internet browser in December 2022. The Korean tech giant addressed the two flaws related to Chromium (CVE-2022-4262 and CVE-2022-3038) through an Internet browser app update after version 19.0.6.

Samsung broke the exploit chain that was leveraging its Chromium-based Internet app and the Mali kernel vulnerability in December, and it appears that the attacks on users in the UAE have stopped. However, one glaring issue remains.

The exploit chain Google detailed today was addressed thanks to Samsung Internet browser updates in December. But one link in the chain, consisting of the massive Mali security vulnerability (CVE-2022-22706), remains unpatched on Samsung devices equipped with Exynos chipsets and Mali GPUs. That is, despite the fact that Mali already provided a fix for its kernel driver exploit as early as January 2022.

Until Samsung mends this issue through a security firmware patch containing the Mali fix, it appears that the majority of Galaxy devices featuring Exynos SoCs remain vulnerable to the Mali GPU kernel driver exploit.

Update: Samsung reached out to us with the following statement “Samsung takes the security of its products very seriously. We have already taken necessary steps to prevent these potential exploit chains by issuing patches for the Samsung Internet app in December 2022. December's updates to the Samsung Internet app disable entry points for the remaining vulnerabilities and ensure devices are protected.

We are actively collaborating with our partners to release patches for the remaining vulnerabilities as early as possible, starting April, and recommend all users keep their devices updated with the latest software to ensure the highest level of protection possible.”

FirmwareGeneralPhone ExynosSamsung Electronics
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Samsung’s device repair network welcomes 300+ more locations

Samsung’s device repair network welcomes 300+ more locations

Samsung's customer care network is expanding. The company announced today that its partnership with Cell Phone Repair (CPR) by Assurant, an Independent Service Provider (ISP) within Samsung's repair network, is opening more than 300 new service locations before the end of 2024. At the beginning of the year, CPR had roughly 100 locations certified by […]

  • By Mihai Matei
  • 7 hours ago
Exynos 1580 vs Exynos 1480: What has improved the most?

Exynos 1580 vs Exynos 1480: What has improved the most?

Last week, Samsung unveiled its new mid-range Exynos chip, the Exynos 1580. It succeeds the Exynos 1480 chip announced last year and brings several improvements. But which are the most significant improvements that you will notice in your day-to-day life? Let us find out in this Exynos 1580 vs. Exynos 1480 comparison. Exynos 1580 vs […]

  • By Asif Iqbal Shaik
  • 10 hours ago
Samsung goes all nostalgic for the ‘glorious Y2K era’

Samsung goes all nostalgic for the ‘glorious Y2K era’

Samsung has become nostalgic for the year 2000 and has partnered with two designers to create new accessories inspired by popular trends of the era. This new collection of accessories, designed for the Galaxy Z Flip 6 and the Galaxy Buds 3, recalls “the simpler and more fun years of our youth,” when the Internet […]

  • By Mihai Matei
  • 6 days ago
Even Galaxy S26 to go full Snapdragon; Exynos to return with Galaxy S27

Even Galaxy S26 to go full Snapdragon; Exynos to return with Galaxy S27

Earlier today, it was revealed that Samsung will exclusively use the Snapdragon 8 Elite chip in all Galaxy S25 models. And Samsung could continue its Snapdragon exclusivity for another year, as the Galaxy S26 series will reportedly use Qualcomm's Snapdragon chips as well. However, Exynos isn't dead in the water and will reportedly return. Galaxy […]

  • By Asif Iqbal Shaik
  • 6 days ago
Good news! All Galaxy S25 models to use Snapdragon 8 Elite globally

Good news! All Galaxy S25 models to use Snapdragon 8 Elite globally

Over the past few months, the chipset used in the Galaxy S25 series has been a point of contention. Since Samsung confidently named the Exynos 2500 during its recent earnings call, the chip was expected to be used in some Galaxy S25 series devices. However, this might not be the case, as all units reportedly […]

  • By Asif Iqbal Shaik
  • 7 days ago
Clever trick from Samsung might fix moisture detection warnings

Clever trick from Samsung might fix moisture detection warnings

Samsung Galaxy phones and tablets boast a high level of water resistance, but the USB ports are not covered, and as everyone knows, water and electronic circuits don't go well together. To avoid water damage and keep water resistance without resorting to USB port covers, Samsung developed a clever software component that automatically detects moisture […]

  • By Mihai Matei
  • 2 weeks ago