Skip to content

Exynos processors, developed by Samsung, have security gaps (they allow remote malicious attacks)

Google has announced that the Exynos processors, developed by Samsung and included in Galaxy, Google Pixel and vivo models, present a security hole that allows cybercriminals to attack and remotely control these devices.

LOOK: Twitch: Of the 100 most watched streamers in the world, only three are women

This bug has been discovered by the team Project Zeroof security analysts who are in charge of finding zero-day attacks, that is, those that are produced by vulnerabilities for which There is no security patch yet.

The company has advanced that from the end of 2022 and the beginning of 2023, this group accounted for a total of 18 zero-day vulnerabilities in Samsung Exynos processors produced by the South Korean technology manufacturer.

Four of these 18 faults, which were considered “more serious” than the others, allowed remote code execution from the internet, so attackers could tamper with the terminal without the interaction of its owner. The only requirement for this is to obtain the phone number of the victims.

LOOK: What happens when you press the power button five times on your cell phone? Doing so could save your life.

“With additional research and development, we believe that attackers could create an operational ‘exploit’ to compromise affected devices silentlythe company has qualified in a statement.

As for the rest of the vulnerabilities, Project Zero has commented that “they were not so serious”, since to exploit them the cybercriminals required local access to the infected devices.

The phones affected by this problem would be the models of Samsung S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 and A04. also terminals vivo (vivo S15, S15, S6, X70, X60 and X30), as well as Google’s Pixel 6 and Pixel 7. Beyond smartphones, wearables with Exynos W920 chipset and vehicles equipped with the Exynos Auto T5123 platform are included.

LOOK: Can’t use ChatGPT? The four best alternatives to the OpenAI chatbot

The manufacturer has commented that companies patches are being developed to fix these vulnerabilities and that Google has already implemented its own (for the vulnerability registered as CVE-2023-24033) on Pixel devices.

For the rest, has been advised to disable WiFi calls and voice calls over the network (VoLTE) in the Settings section of your devices.

Source: Elcomercio

Share this article:
globalhappenings news.jpg
most popular