Tag: Exynos

  • Samsung will patch the last dangerous Exynos modem vulnerability in April

    Samsung will patch the last dangerous Exynos modem vulnerability in April

    Earlier this month we told you about a zero-day vulnerability which means that a flaw was previously unknown to the software vendor and has been unpatched. The vulnerability affected the Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5123. Armed with nothing but the targeted device’s phone number, attackers can access the device.

    We know that Pixel 6 and Pixel 7 models were affected, but the flaw has been patched on these phones with the March security update which has now been released for the Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7 and the Pixel 7 Pro. Other phones affected include Exynos-powered phones in the Samsung Galaxy S22 line. These models were sold in the U.K. and Europe. Other Samsung phones with the flaw include models in the mid-range Galaxy A and Galaxy M lines:

    • Galaxy A71
    • Galaxy A53
    • Galaxy A33
    • Galaxy A21s
    • Galaxy A13
    • Galaxy A12
    • Galaxy A04 series
    • Galaxy M33
    • Galaxy M13
    • Galaxy M12
    • Galaxy Watch 5 series
    • Galaxy Watch 4 series
    Also affected are a few Vivo models such as the S16, S15, S6, X70, X60, and X30 series.

    A Samsung community manager posted on the Samsung U.S. community site and said that five out of the six vulnerabilities found in the aforementioned Exynos modems were patched in March and the remaining flaw will be patched next month. Interestingly, Samsung initially came to the conclusion that the flaws were not severe.

    The community manager wrote last week, “Hello, We understand the concern of vulnerabilities. Samsung takes the safety of our customers very seriously. After determining 6 vulnerabilities may potentially impact select Galaxy devices, of which none were ‘severe’, Samsung released security patches for 5 of these in March. Another security patch will be released in April to address the remaining vulnerability. As always, we recommend that all users keep their devices updated with the latest software to ensure the highest level of protection possible.”
    Until the last vulnerability is patched in April, the Samsung and possibly the Vivo handsets listed above are at risk of being compromised at the baseband level. Thus, Google’s Project Zero research team recommends that users of phones still vulnerable should disable Wi-Fi calling and Voice-over-LTE (VoLTE).
  • Vulnerability not yet fixed leaves millions of Android phones at risk

    Vulnerability not yet fixed leaves millions of Android phones at risk

    According to Google’s Project Zero team of security analysts, millions of Android handsets are vulnerable to an unpatched vulnerability known as CVE-2022-33917. CVE stands for Common Vulnerabilities and Exposures , and each CVE number refers to a specific flaw. The aforementioned CVE is a vulnerability that affects Android devices that are equipped with ARM’s Mali GPU. That means that Google Pixel and Samsung Galaxy handsets are affected along with Android smartphones made by many other manufacturers.
    Until the patch is disseminated, attackers can potentially exploit the flaw. Google says that this would allow attackers to “continue to read and write physical pages after they had been returned to the system.” Furthermore, the company adds that “by forcing the kernel to reuse these pages as page tables, an attacker with native code execution in an app context could gain full access to the system, bypassing Android’s permissions model and allowing broad access to user data.”
    Project Zero notes that it told ARM about the vulnerabilities and ARM “promptly” fixed the issues in July and August of this year. ARM assigned the CVE-2022-33917 number to the flaw. But Google later found “that all of our test devices which used Mali are still vulnerable to these issues. CVE-2022-36449 is not mentioned in any downstream security bulletins.” In other words, devices made by Google’s own Pixel team, Samsung, Oppo,  and Xiaomi were never patched and still have this exploitable vulnerability.
    Keep in mind that the phones at risk sport a Mali GPU which eliminates devices powered by a Snapdragon chipset. However, handsets using Google Tensor, Exynos, or MediaTek chips need to be patched. The good news is that Google is testing a patch that is expected to be pushed out “in the coming weeks.” Phone manufacturers building Android devices will also need to include it.
    Google’s statement reads, “The fix provided by Arm is currently undergoing testing for Android and Pixel devices and will be delivered in the coming weeks. Android OEM partners will be required to take the patch to comply with future SPL requirements.”
    And Google also has words of wisdom for Android vendors trying to prevent a similar incident from popping up in the future. The company makes it clear that vendors have a responsibility to patch their software flaws just like Android users must download security updates as soon as they are received.

    “Just as users are recommended to patch as quickly as they can once a release containing security updates is available, so the same applies to vendors and companies. Minimizing the “patch gap” as a vendor in these scenarios is arguably more important, as end users (or other vendors downstream) are blocking on this action before they can receive the security benefits of the patch,” Google wrote.

    The search giant added that “Companies need to remain vigilant, follow upstream sources closely, and do their best to provide complete patches to users as soon as possible.”

    Google has not said that the vulnerability has been exploited by any attackers but for the time being it remains a flaw that can be used to steal the personal data on certain Android phones. When the update does arrive-and Google has said that it will be coming soon-if you have an Android phone at risk, install the update immediately. You can quickly determine if you device is vulnerable by looking at the specs for your phone on PhoneArena and checking to see the manufacturer of the GPU on the device.

    If it shows that you have an ARM Mali graphics processing unit (GPU), your device is at risk. Keep checking in as we will update this story when the patch is disseminated.

  • Samsung could release three Exynos chips this year

    Samsung could release three Exynos chips this year

    Samsung will unveil three Exynos chips this year, claims leaker Ice Universe. The 2021 lineup presumably includes a flagship SoC (Exynos 22xx), a mid-tier chip (Exynos 12xx), and an entry-level silicone (Exynos 8xx).

    The Exynos 22xx will likely succeed the Exynos 2100 that powers the European version of the Galaxy S21 series. It supposedly has the model number 9925 and it may feature an AMD GPU.

    The Exynos 12xx will apparently replace the Exynos 1080, and it will probably also swap out the Mali GPU for AMD’s graphics.

    The Exynos 8xx is new on the radar, and we wonder if it has anything to do with a chip recently spotted by Galaxy Club.

    The chip bears the model number S5E5515, which is not very telling, thanks to Samsung’s inconsistent naming convention.

    It does not seem to be a high-end SoC as the model number is not in line with recent flagship chips: Galaxy 10’s Exynos 9820 had the number S5E9820, Galaxy S20’s Exynos 990 had S5E9830, and Galaxy S21’s Exynos 2100 has S5E9840.

    S5E5515 is not consistent with recent mid-tier Exynos chips either. The Exynos 1080 is S5E9815, the Exynos 980 is S5E9630, and Exynos 850 is S5E3830.

    The publication has made a wild guess and believes that the S5E5515 is a lower-mid-tier chip that will sit between the Exynos 850 and Exynos 1080. It is also expected to have an integrated 5G modem.

    The SoC could also turn out to be a non-smartphone chip. Samsung is already believed to be working on a new processor for wearables like AR glasses.

  • Samsung Elec to supply Exynos processors for Audi vehicles

    Samsung Elec to supply Exynos processors for Audi vehicles

    Tech giant Samsung Electronics said on Wednesday it will start supplying Volkswagen’s Audi with Exynos processors for the carmaker’s infotainment systems, expanding its chip sales for the auto business.

    Samsung said in a statement its Exynos processors will power up to four in-vehicle displays for Audi’s next-generation infotainment system without elaborating on the contract value or what vehicles Audi will use the chips for.

    Car Infotainment systems for cars are for displaying information such as navigation and playing audio or video. The systems also increasingly allow drivers to connect their phones to their vehicles.

    The world’s top maker of smartphones and memory chips has been trying to boost sales of components for automobiles to boost growth. Samsung already supplies memory chips to Audi.