DEAL Galaxy S24 FE, Galaxy Watch 7. Subscribe today and be the first to learn about One 7 beta!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Security flaw in Qualcomm modems affects millions of 5G Samsung devices

Phone
By 

Last updated: May 12th, 2021 at 15:54 UTC+02:00

A serious security flaw affecting Qualcomm's mobile station modems (MSM) was recently disclosed by security research team Check Point, who claims that the vulnerability could be exploited to inject malicious code into the phone by using the Android operating system itself as an entry point. The affected chip(s) are reportedly responsible for connecting nearly 40% of all smartphones in the world, including high-end phones from Samsung and other OEMs.

The research team found that if a researcher wants to explore the latest 5G code in devices powered by Qualcomm's modems by implementing a debugger, the easiest way to do that is to exploit MSM data services through QMI' (Qualcomm MSM Interface). The investigation revealed a vulnerability in modem data service that can be used to control the modem and dynamically patch it from the application processor.'

Numerous Samsung Galaxy devices remain vulnerable to this threat

The good news is that although the security flaw was publicly disclosed earlier today, it has already been addressed and patched by Qualcomm in December 2020. The issue was kept under wraps for obvious security reasons.

The not-so-good news is that numerous smartphones developed by Samsung (as well as other OEMs) are still vulnerable as of this writing. As always, if a part manufacturer such as Qualcomm releases a patch for its hardware, it's up to smartphone OEMs to distribute the update as they see fit. And because we live in the world of Android OS where fragmentation is par for the course, some devices will be updated sooner than others, with availability differing by region.

Now, because Check Point has decided to make this issue public, this indicates that smartphone OEMs — including Samsung — should now be in the process of updating their devices to address the security flaw, however, it may take some time.

The May 2021 security patch is now rolling out for numerous Galaxy devices, but it might not contain the necessary fixes for this issue. The security patch does include a fix for devices powered by both Exynos and Qualcomm chipsets — one that was reported in December — but it doesn't seem to match Check Point's description. Qualcomm has classified the vulnerability as ‘CVE-2020-11292,' and this classification was not mentioned in Samsung's latest security bulletin.

Update: Samsung has since updated the May 2021 security bulletin and confirmed that the security flaw classified as “CVE-2020-11292” has been gradually patched since January.

Original story continues:

At the end of the day, what this means is that Samsung is, or should soon be in the process of releasing a new security patch that fixes Qualcomm's security flaw. However, we're not sure how many models are affected or if the May 2021 security patch addresses it in any capacity.

Either way, mobile device users should make sure that they're always running the latest security updates. SamMobile readers can refer to our new online tool to check if their phone runs the latest security patch available in their region.

Via FirmwareGeneralPhoneTablet 5GQualcomm
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Samsung planning to use Qualcomm chips in home appliances

Samsung planning to use Qualcomm chips in home appliances

A few weeks ago, it was reported that Samsung had decided to use Qualcomm's Snapdragon chips inside all Galaxy S25 smartphones. Now, it is being claimed that Qualcomm chips will be used in more Samsung products, including home appliances. This move is likely taken to have better negotiating power over chip pricing and to make appliances […]

  • By Asif Iqbal Shaik
  • 1 hour ago
Google to follow Samsung’s lead by using custom chips for smartwatches

Google to follow Samsung’s lead by using custom chips for smartwatches

Qualcomm was way too slow in bringing advanced chips for smartwatches, and that is when Apple took a huge leap forward. Samsung didn't depend on Qualcomm and developed in-house Exynos chips for Galaxy Watches. While Google switched from Exynos to Snapdragon chips for second and third-generation Pixel Watches, it could switch to in-house chips in […]

  • By Abid Iqbal Shaik
  • 1 day ago
One UI 7 said to be biggest improvement in Samsung’s history

One UI 7 said to be biggest improvement in Samsung’s history

Samsung was expected to release the Android 15-based One UI 7.0 beta update in late July 2024, but it was delayed. It still hasn't been released, and the word is that the update won't be released for quite some time. However, this delay could be a boon for all Samsung users, as One UI 7.0 […]

  • By Asif Iqbal Shaik
  • 2 days ago
Want to catch up on Snapdragon 8 Elite? Here’s our full overview

Want to catch up on Snapdragon 8 Elite? Here’s our full overview

If you've been with us since the beginning of the week, you likely have an idea of just how crazy Qualcomm's new chip is. We had the opportunity to attend Snapdragon Summit 2024 in Hawaii and got all the information we could from Qualcomm about the Snapdragon 8 Elite chip. We talked about it a […]

  • By Mihai Matei
  • 6 days ago
Qualcomm CMO sheds light on the regional co-marketing wins with Samsung

Qualcomm CMO sheds light on the regional co-marketing wins with Samsung

Samsung and Qualcomm both attach a lot of importance to their longstanding partnership, evidenced by the fact that the head of Samsung's mobile division, TM Roh, made an in-person appearance on stage during the ongoing Snapdragon Summit 2024, where Qualcomm unveiled the Snapdragon 8 Elite. “We love Samsung,” Qualcomm CEO Cristiano Amon said as he […]

  • By Adnan Farooqui
  • 6 days ago
Snapdragon 8 Elite Geekbench, other benchmarks put gains in perspective

Snapdragon 8 Elite Geekbench, other benchmarks put gains in perspective

Qualcomm officially announced the Snapdragon 8 Elite chipset earlier this week at the ongoing Snapdragon Summit 2024 in Maui, Hawaii. It's a big launch for the company as this is the first time that its custom Oryon cores have been integrated into its mobile platform. Qualcomm did say last year that it would bring Oryon […]

  • By Adnan Farooqui
  • 6 days ago