NIST, the National Institute of Standards and Technology, is warning about a new problem identified in Samsung, where the authenticity of the user requesting to lock the device cannot be verified.
This app offers a bunch of services to Samsung phone owners, such as finding, locking, and disabling their lost or stolen device. Security expert Mohamed Abdelbaset Elnob, from Egypt, discovered this problem that allows third parties to lock or unlock the device, and even make it ring.
This is done through an HTML page and is called Cross-Site Request Forgery (CSRF or XSRF), where the user is redirected to a new page with malicious code. From there, anyone can gain full rights to the device, such as purchasing something, viewing the owner's information, and even changing it.
The first time the user opens the Link is the most dangerous, since from there on, someone can easily gain access to the device and lock it, leading the victim to reset their passwords via their Google account.
Below is how the process works in the “Find My Mobile” application
https://www.youtube.com/watch?feature=player_embedded&v=Q3adkpOEjyI
NIST identified this problem, with the code CVE-2014-8346 , and gave it a severity rating of 10.0.

