HomeSecurity11 Zero-Day Vulnerabilities Affect the Samsung Galaxy S6 Edge

11 Zero-Day Vulnerabilities Affect Samsung Galaxy S6 Edge

Google's Project Zero security team spent the past week searching for security flaws affecting Samsung. The results: 11 new zero-day vulnerabilities came to light in just seven days.

 

Samsung Galaxy S6 Edge
Most vulnerabilities affect phone drivers

 

[alert variation=”alert-success”]Project Zero is a Google program that aims to improve the overall security of popular applications. The Project Zero team is made up of top security researchers with the sole mission of identifying, reporting, and fixing critical security flaws in widely used software.[/alert]

 

It all started as a "game"..

Having been divided into two teams (“Americans vs. Europeans”), Project Zero researchers acted for the common good, competing to see which team would be able to uncover the most bugs in Samsung’s flagship, the Galaxy S6 Edge.

[signoff icon=”icon-target”]This particular device was chosen because of its large userbase, but also because of the modified version of Android it has.[/signoff]

The team tried to focus on new bugs introduced when adapting the device's operating system to the hardware and to focus on remote exploits that allow unauthorized access to photos, messages, and contact information.

 

A total of 11 zero-days were identified, the majority of which concern Samsung drivers and media editing utilities.

Although the project started as a game, things took a different turn after 11 critical “zero-day” vulnerabilities were identified on the device.

“Overall, we were able to identify a significant number of high-criticality vulnerabilities, although there were some effective security measures on the device that slowed us down,” says Google researcher Natalie Silvanovich. “The weak areas appear to be device drivers and media processing,” she adds.

 

The researchers responsibly reported the issues to Samsung, eight of which have already been fixed through updates released as part of the company's scheduled Maintenance Release, while the remaining three are expected to be resolved in November.

 

Below is a table with all the errors that have been found.

CVE-2015-7888FixedDirectory traversal bug that allowed an attacker to write files to an arbitrary path as the system user.
CVE-2015-7889FixedAn unprivileged application can cause the user's emails to be forwarded to another account.
CVE-2015-7890FixedBuffer overflow vulnerability in the Exynos Seiren Audio driver that led memory corruption to occur.
CVE-2015-7891FixedThe Graphics 2D driver is accessible by unprivileged users/applications.
CVE-2015-7892FixedThe m2m1shot driver causes a buffer overflow.
CVE-2015-7893Not FixedJavaScript embedded in an email message can be executed in the email client.
CVE-2015-7894FixedDownloading and scanning an image causes memory corruption. Allows privilege escalation.
CVE-2015-7895Not FixedOpening an image in the Gallery app causes the app to crash and escalates privileges.
CVE-2015-7896FixedDownloading and scanning an image causes memory corruption. Allows privilege escalation.
CVE-2015-7897FixedDownloading and scanning an image causes memory corruption. Allows privilege escalation.
CVE-2015-7898Not FixedOpening an image in the Gallery app causes the app to crash and escalate privileges.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS