{"id":5182,"date":"2022-04-13T07:13:19","date_gmt":"2022-04-13T05:13:19","guid":{"rendered":"https:\/\/allcore.be\/news\/update-your-samsung-phone-as-soon-as-possible-to-prevent-it-from-being-hijacked\/"},"modified":"2023-06-21T11:58:40","modified_gmt":"2023-06-21T09:58:40","slug":"update-your-samsung-phone-as-soon-as-possible-to-prevent-it-from-being-hijacked","status":"publish","type":"post","link":"https:\/\/allcore.be\/en\/news\/update-your-samsung-phone-as-soon-as-possible-to-prevent-it-from-being-hijacked\/","title":{"rendered":"Update your Samsung phone as soon as possible to prevent it from being hijacked"},"content":{"rendered":"\n<p>Kryptowire, a company that provides mobile security and privacy solutions, has announced that it has discovered a serious security vulnerability in Samsung devices running Android versions 9 through 12. The vulnerability (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-22292\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-22292<\/a>) allows local applications to mimic system-level activity and &#8220;hijack&#8221; crucial secure functionality.<\/p>\n\n<p>After hijacking your device, attackers are given the option to perform a factory reset (read: erase all user data), make phone calls (including to emergency numbers such as 112), install\/uninstall apps and install https security. weaken it by installing arbitrary <a href=\"https:\/\/en.wikipedia.org\/wiki\/Root_certificate\" target=\"_blank\" rel=\"noreferrer noopener\">root certificates<\/a>. All this from untrusted apps running in the background and without end user consent.<\/p>\n\n<p>The CVE-2022-22292 vulnerability was notified to Samsung on November 27, 2021, and received a &#8220;High&#8221; severity rating from the manufacturer. In February 2022, Samsung patched the vulnerability as part of its ongoing <a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\" target=\"_blank\" rel=\"noreferrer noopener\">Security Maintenance Release<\/a> (SMR) process. The vulnerability resides in the pre-installed Phone app that runs with system privileges on Samsung devices running Android versions 9 through 12. The Phone app has an insecure component that allows local apps to perform privileged actions without user consent.<\/p>\n\n<p>If for whatever reason you haven&#8217;t updated your Samsung phone yet, we think it&#8217;s an excellent time to do so. Technical information about the Samsung vulnerability can be found <a href=\"https:\/\/www.kryptowire.com\/blog\/start-arbitrary-activity-app-components-as-the-system-user-vulnerability-affecting-samsung-android-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>. <\/p>\n\n<p><\/p>\n\n<p>Source: <a href=\"https:\/\/nl.hardware.info\/nieuws\/81168\/update-je-samsung-telefoon-zo-snel-mogelijk-om-te-voorkomen-dat-hij-gekaapt-wordt\" target=\"_blank\" rel=\"noreferrer noopener\">Hardware.info<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kryptowire, a company that provides mobile security and privacy solutions, has announced that it has discovered a serious security vulnerability in Samsung devices running Android versions 9 through 12. The vulnerability (CVE-2022-22292) allows local applications to mimic system-level activity and &#8220;hijack&#8221; crucial secure functionality. After hijacking your device, attackers are given the option to perform [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":4963,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5182","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts\/5182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/comments?post=5182"}],"version-history":[{"count":1,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts\/5182\/revisions"}],"predecessor-version":[{"id":5183,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts\/5182\/revisions\/5183"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/media\/4963"}],"wp:attachment":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/media?parent=5182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/categories?post=5182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/tags?post=5182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}