Developer Finds Security Hole in Galaxy Note II, S2
December 17, 2012 8:31 PM
comment(s) - last by
Memory permissions raise danger of local attacks
Samsung Electronics Comp., Ltd. (
) the top maker of Android smartphones in the world (or any kind of phones, for that matter), received some unwelcome news on Monday, when a developer going by the handle "alephzain" posted details on Microsoft Corp.'s (
) XNA developers forum regarding memory permissions security holes in some of Samsung's top devices.
In order to give their
a dedicated line from the camera to the memory, Samsung opened up permissions to the on-chip DRAM. The only issue is that it appears to have opened its memory for writing to all users.
That's good news for modders who could use it to obtain root for the purpose of installing custom builds of Android like Cyanogen. Bu at it's bad news from a security perspective.
The Galaxy Note II
The flaw appears to affect a number of top Samsung devices, including the
Galaxy Note II
, the Galaxy S2, and the Meizu MX. Comments the developer who found the flaw, "The good news is we can easily obtain root on these devices and the bad is there is no control over it."
Generally to do something truly malicious with the flaw, you would have to use a trojan app equipped with memory dumping or memory injection functionality. But given the
success of past trojans against Android-rival Apple
, Inc. (
) the possibility of this flaw being exploited in the wild should not be ruled out.
This article is over a month old, voting and posting comments is disabled
12/18/2012 6:07:12 AM
I've been waiting three days for this one to see what spin would be put on it and y'know I'm not disappointed. In fact my expectations have been exceeded.
Let's ignore the sheer scale (in terms of products) and sheer seriousness of this situation (wilful Direct Memory Access on a network-connected device) but instead deflect attention towards the fruity ones with a link to a completely irrelevant article that was scotched six months ago in any case and was a complete non-story.
No matter about all those Samsung owners who will be blissfully unaware of the mess going on in their pocket because they don't read tech websites (I mean proper tech websites, not this one obviously) and have no idea just how big a clusterfuck Samsung have made here and will probably actually be completely unaware of it and therefore will not take steps to mitigate the problem.
Good game Mick. Clown.
12/18/2012 3:23:06 PM
Looks like the story/article was taken down? It shows up as blank, even after refreshing.
"Spreading the rumors, it's very easy because the people who write about Apple want that story, and you can claim its credible because you spoke to someone at Apple." -- Investment guru Jim Cramer
Apple Aims to Tack on Galaxy Note II and 5 Other Products to Existing Lawsuit
November 26, 2012, 2:05 PM
Symantec: Flashback Trojan for Mac Generates $10,000/Day
May 1, 2012, 1:46 PM
Samsung Reveals Quad-Core Exynos 4 for Galaxy S3 Superphone
April 26, 2012, 1:19 PM
Quick Note: Google Chromebooks Now Coming with 1TB of Google Drive Space
November 21, 2014, 1:20 PM
Xiaomi Aims to be #1 Smartphone OEM Within 10 Years, Apple Urges Caution
November 21, 2014, 9:33 AM
Quick Note: Samsung's Request to Dismiss Microsoft Lawsuit is Rejected
November 20, 2014, 12:53 PM
Amazon Offers "The Washington Post" Free for Six Months to Kindle Fire Owners
November 20, 2014, 7:41 AM
Apple Watch Screen Resolution, App Limitations are Laid Bare by Developer Kit
November 19, 2014, 11:31 PM
Apple Replaces “FREE” Label with “GET” on App Downloads in iTunes App Store
November 19, 2014, 5:38 PM
Most Popular Articles
Austrian Pilots Call Surface 3 Pro Flight Bag a "Dream Come True"
November 14, 2014, 2:00 PM
Wal-Mart: Miss Thanksgiving, Get Xbox One + Master Chief Collection for $299
November 17, 2014, 9:40 PM
Nokia Explores Two Paths Back to the Smartphone Market
November 14, 2014, 9:05 PM
It's Official: Twitter is Profitable "Junk"
November 16, 2014, 10:45 PM
U.S. Marshals Using Fake, Airplane-based Cell Towers to Scan Cell Phones of Americans
November 14, 2014, 9:05 AM
Latest Blog Posts
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information