Developer Finds Security Hole in Galaxy Note II, S2
December 17, 2012 8:31 PM
comment(s) - last by
Memory permissions raise danger of local attacks
Samsung Electronics Comp., Ltd. (
) the top maker of Android smartphones in the world (or any kind of phones, for that matter), received some unwelcome news on Monday, when a developer going by the handle "alephzain" posted details on Microsoft Corp.'s (
) XNA developers forum regarding memory permissions security holes in some of Samsung's top devices.
In order to give their
a dedicated line from the camera to the memory, Samsung opened up permissions to the on-chip DRAM. The only issue is that it appears to have opened its memory for writing to all users.
That's good news for modders who could use it to obtain root for the purpose of installing custom builds of Android like Cyanogen. Bu at it's bad news from a security perspective.
The Galaxy Note II
The flaw appears to affect a number of top Samsung devices, including the
Galaxy Note II
, the Galaxy S2, and the Meizu MX. Comments the developer who found the flaw, "The good news is we can easily obtain root on these devices and the bad is there is no control over it."
Generally to do something truly malicious with the flaw, you would have to use a trojan app equipped with memory dumping or memory injection functionality. But given the
success of past trojans against Android-rival Apple
, Inc. (
) the possibility of this flaw being exploited in the wild should not be ruled out.
This article is over a month old, voting and posting comments is disabled
12/18/2012 6:07:12 AM
I've been waiting three days for this one to see what spin would be put on it and y'know I'm not disappointed. In fact my expectations have been exceeded.
Let's ignore the sheer scale (in terms of products) and sheer seriousness of this situation (wilful Direct Memory Access on a network-connected device) but instead deflect attention towards the fruity ones with a link to a completely irrelevant article that was scotched six months ago in any case and was a complete non-story.
No matter about all those Samsung owners who will be blissfully unaware of the mess going on in their pocket because they don't read tech websites (I mean proper tech websites, not this one obviously) and have no idea just how big a clusterfuck Samsung have made here and will probably actually be completely unaware of it and therefore will not take steps to mitigate the problem.
Good game Mick. Clown.
12/18/2012 3:23:06 PM
Looks like the story/article was taken down? It shows up as blank, even after refreshing.
"If you look at the last five years, if you look at what major innovations have occurred in computing technology, every single one of them came from AMD. Not a single innovation came from Intel." -- AMD CEO Hector Ruiz in 2007
Apple Aims to Tack on Galaxy Note II and 5 Other Products to Existing Lawsuit
November 26, 2012, 2:05 PM
Symantec: Flashback Trojan for Mac Generates $10,000/Day
May 1, 2012, 1:46 PM
Samsung Reveals Quad-Core Exynos 4 for Galaxy S3 Superphone
April 26, 2012, 1:19 PM
Quick Note: Toshiba to Restructure PC Business, Cut 900 Jobs Worldwide
September 18, 2014, 1:40 PM
Samsung Galaxy Note 4 U.S. Pre-orders Start Sept 19, Launches Oct 14
September 18, 2014, 10:15 AM
Amazon Releases New and Refreshed Kindle Fire Tablets, Announces Fire OS 4
September 17, 2014, 10:23 PM
Apple Launches iOS 8 for iPads, iPhones
September 17, 2014, 1:54 PM
Apple Cripples NFC in iPhone 6, 6+ With Developer Ban
September 17, 2014, 1:00 PM
5.7" ZTE ZMAX "Phablet" Coming to T-Mobile Sept 24 for $252
September 17, 2014, 11:50 AM
Most Popular Articles
Quick Note: Buy an Xbox One Sept 7-13, Get a Free Game
September 4, 2014, 10:42 AM
Apple Announces Its Smartwatch: The $349 Apple Watch
September 9, 2014, 2:09 PM
Dell Announces "World's Thinnest" Tablet: The Venue 8 7000 Series
September 11, 2014, 8:51 AM
Windows 9's Latest Metro Start Menu Leaks, German Site Accidentally Outs Leaker
September 11, 2014, 8:36 PM
T-Mobile Launches Un-carrier 7.0, Beefs Up Wi-Fi Calling
September 11, 2014, 2:56 PM
Latest Blog Posts
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information