
Google has warned users of certain Android phones to turn off WiFi calling and VoLTE on their devices as numerous zero-day vulnerabilities have been detected on Samsung chipsets. These devices are at a high risk of getting hacked.
All that it’ll take is your phone number for a hacker to get complete control over your device remotely.
The hacker will make a special call to your device, and within minutes, you’ll lose all control over it.
These device owners, watch out!
The vulnerability affects only those devices that use the Exynos chipset made by Samsung’s semiconductor division. This means the devices at risk include the international version of Samsung Galaxy S22, Pixel 6 and 7, Galaxy Watch 4 and 5, and a few other mid-range Samsung phones.
These devices are vulnerable because the vulnerable chipset contains the baseband responsible for processing voice calls. That’s why US users of Samsung Galaxy S22 are safe because the device uses Qualcomm Snapdragon chips to process calls.
What can you do to stay safe?
While turning off WiFi calling and VoLTE are the only recommended ways to minimize the chances of attack, it’s still unknown if following this process is even possible in some devices.
A Reddit user posted a screenshot of their device settings where the option to turn off VoLTE was not available to change. Not to mention, doing so will diminish your device’s calling capabilities.
This isn’t the first time that a series of malicious bugs have been found in this Samsung chipset.
One of the 4 bugs that have been tracked is designated as CVE-2023-24033. Together, these 4 bugs are helping hackers embed and run malicious codes on the target device.
Plus, since the baseband of a device usually has privileged access to the device’s hardware, a vulnerability poses a huge threat to the entire system.
Tim Willis, the head of the bug-hunting team at Google’s Project Zero, said that the team identified 18 such malicious bugs in Samsung’s Exynos cellular modem firmware between late 2022 and early 2023. He also confirms that it’s only these 4 bugs that need to be fixed urgently.
Meanwhile, both Google and Samsung have been working tirelessly to develop a fix for these vulnerabilities.
The other 14 issues aren’t that dangerous because the hacker will need local access to the target device if they wish to exploit those vulnerabilities.
Earlier this month, Google launched a patch for the vulnerable Pixel models. Samsung, too, came up with a CVE-2023-24033 (the deadliest bug of all) but is yet to deliver them to the masses.
For the other three unnamed bugs, there’s no update on whether their security patches have been developed or not.
Read More
Erasmo Drews
