Samsung’s Exynos chips cited for potentially hackable flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-26072 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 512 An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Emergency number list. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-26075 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 512 An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Service Area List. NVD description · AI analysis pending | 9.8 | <1% |
| — |
Full article476 words · extracted from therecord.media · click to collapse
Important Samsung-made chips inside several popular Android devices have serious vulnerabilities that could allow attackers to “silently and remotely” compromise them, researchers said Thursday. Google’s Project Zero team said Thursday that the Exynos modems used in multiple series of Samsung, Pixel and Vivo phones could be attacked “with no user interaction,” with methods that “require only that the attacker know the victim's phone number.” The report cites 18 bugs in total, all of them zero-day vulnerabilities that Samsung had not patched for consumers as of Thursday, Project Zero said. Samsung’s semiconductor unit has noted the flaws. Like a household modem, the chips translate cellular data for the phone to use — a process known as “internet to baseband.” The researchers said it’s possible for users to avoid trouble if they “turn off Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings.” Typically programs like Project Zero set a deadline for a company to remedy serious vulnerabilities before going public with the information. In this case, Samsung was given 90-day periods to address the zero-days, Project Zero said, but some of those have elapsed, and the team decided it was important to warn the public about the entire set. Several of the flaws do not yet have numbers in the “CVE” database that researchers use to track vulnerabilities, Project Zero said. The Exynos vulnerabilities break down like this: Project Zero’s survey of potentially affected devices includes:
No previous article
No new articles
Joe Warminsky
has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/samsung-exynos-chips-cited-for-hackable-flaws