Google's Project Zero security team spent the past week searching for security flaws affecting Samsung. The results: 11 new zero-day vulnerabilities came to light in just seven days.

[alert variation=”alert-success”]Project Zero is a Google program that aims to improve the overall security of popular applications. The Project Zero team is made up of top security researchers with the sole mission of identifying, reporting, and fixing critical security flaws in widely used software.[/alert]
It all started as a "game"..
Having been divided into two teams (“Americans vs. Europeans”), Project Zero researchers acted for the common good, competing to see which team would be able to uncover the most bugs in Samsung’s flagship, the Galaxy S6 Edge.
[signoff icon=”icon-target”]This particular device was chosen because of its large userbase, but also because of the modified version of Android it has.[/signoff]
The team tried to focus on new bugs introduced when adapting the device's operating system to the hardware and to focus on remote exploits that allow unauthorized access to photos, messages, and contact information.
A total of 11 zero-days were identified, the majority of which concern Samsung drivers and media editing utilities.
Although the project started as a game, things took a different turn after 11 critical “zero-day” vulnerabilities were identified on the device.
“Overall, we were able to identify a significant number of high-criticality vulnerabilities, although there were some effective security measures on the device that slowed us down,” says Google researcher Natalie Silvanovich. “The weak areas appear to be device drivers and media processing,” she adds.
The researchers responsibly reported the issues to Samsung, eight of which have already been fixed through updates released as part of the company's scheduled Maintenance Release, while the remaining three are expected to be resolved in November.
Below is a table with all the errors that have been found.
| CVE-2015-7888 | Fixed | Directory traversal bug that allowed an attacker to write files to an arbitrary path as the system user. |
| CVE-2015-7889 | Fixed | An unprivileged application can cause the user's emails to be forwarded to another account. |
| CVE-2015-7890 | Fixed | Buffer overflow vulnerability in the Exynos Seiren Audio driver that led memory corruption to occur. |
| CVE-2015-7891 | Fixed | The Graphics 2D driver is accessible by unprivileged users/applications. |
| CVE-2015-7892 | Fixed | The m2m1shot driver causes a buffer overflow. |
| CVE-2015-7893 | Not Fixed | JavaScript embedded in an email message can be executed in the email client. |
| CVE-2015-7894 | Fixed | Downloading and scanning an image causes memory corruption. Allows privilege escalation. |
| CVE-2015-7895 | Not Fixed | Opening an image in the Gallery app causes the app to crash and escalates privileges. |
| CVE-2015-7896 | Fixed | Downloading and scanning an image causes memory corruption. Allows privilege escalation. |
| CVE-2015-7897 | Fixed | Downloading and scanning an image causes memory corruption. Allows privilege escalation. |
| CVE-2015-7898 | Not Fixed | Opening an image in the Gallery app causes the app to crash and escalate privileges. |
