ADVERTISEMENT
  • Home
  • World News
  • Sports
  • Forex
  • Crypto
  • Tech News
  • Fashion
  • Entertainment
  • Lifestyle
  • More
    • Freelancer
    • Health & Fitness
    • Culture
seelatestnews.com
No Result
View All Result
  • Home
  • World News
  • Sports
  • Forex
  • Crypto
  • Tech News
  • Fashion
  • Entertainment
  • Lifestyle
  • More
    • Freelancer
    • Health & Fitness
    • Culture
No Result
View All Result
seelatestnews.com
No Result
View All Result
Home Tech News

Google tells users of some Android phones: Nuke voice calling to avoid infection

seelatestnews by seelatestnews
March 17, 2023
in Tech News
0
Google tells users of some Android phones: Nuke voice calling to avoid infection
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


Enlarge / Images of the Samsung Galaxy S21, which runs with an Exynos chipset.

Samsung

Google is urging owners of certain Android phones to take urgent action to protect themselves from critical vulnerabilities that give skilled hackers the ability to surreptitiously compromise their devices by making a specially crafted call to their number.  It’s not clear if all actions urged are even possible, however, and even if they are, the measures will neuter devices of most voice-calling capabilities.

The vulnerability affects Android devices that use the Exynos chipset made by Samsung’s semiconductor division. Vulnerable devices include the Pixel 6 and 7, international versions of the Samsung Galaxy S22, various mid-range Samsung phones, the Galaxy Watch 4 and 5, and cars with the Exynos Auto T5123 chip. These devices are ONLY vulnerable if they run the Exynos chipset, which includes the baseband that processes signals for voice calls. The US version of the Galaxy S22 runs a Qualcomm Snapdragon chip.

A bug tracked as CVE-2023-24033 and three others that have yet to receive a CVE designation make it possible for hackers to execute malicious code, Google’s Project Zero vulnerability team reported on Thursday. Code-execution bugs in the baseband can be especially critical because the chips are endowed with root-level system privileges to ensure voice calls work reliably.

“Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number,” Project Zero’s Tim Willis wrote. “With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.”

Advertisement

Earlier this month, Google released a patch for vulnerable Pixel models. Samsung has released an update patching CVE-2023-24033, but it has not yet been delivered to end users. There’s no indication Samsung has issued patches for the other three critical vulnerabilities. Until vulnerable devices are patched, they remain vulnerable to attacks that give access at the deepest level possible.

The threat prompted Willis to put this advice at the very top of Thursday’s post:

Until security updates are available, users who wish to protect themselves from the baseband remote code execution vulnerabilities in Samsung’s Exynos chipsets can turn off Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings. Turning off these settings will remove the exploitation risk of these vulnerabilities.

The problem is, it’s not entirely clear that it’s possible to turn off VoLTE, at least on many models. A screenshot one S22 user posted to Reddit last year shows that the option to turn off VoLTE is grayed out. While that user’s S22 was running a Snapdragon chip, the experience for users of Exynos-based phones is likely the same.

And even if it is possible to turn off VoLTE, doing so in conjunction with turning off Wi-Fi may turn phones into little more than tiny tablets running Android. VoLTE came into widespread use a few years ago, and since then most carriers in North America have stopped supporting older 3G and 2G frequencies.

Samsung representatives said in an email that the company in March released security patches for five of six vulnerabilities that “may potentially impact select Galaxy devices” and will patch the sixth flaw next month. The email didn’t answer questions asking if any of the patches are available to end users now or whether it’s possible to turn off VoLTE.

Advertisement

A Google representative, meanwhile, declined to provide the specific steps for carrying out the advice in the Project Zero writeup. Readers who figure out a way are invited to explain the process (with screenshots, if possible) in the comments section.

Because of the severity of the bugs and the ease of exploitation by skilled hackers, Thursday’s post omitted technical details. In its product security update page, Samsung described CVE-2023-24033 as a “memory corruption when processing SDP attribute accept-type.”

“The baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to a denial of service or code execution in Samsung Baseband Modem,” the advisory added. “Users can disable WiFi calling and VoLTE to mitigate the impact of this vulnerability.”

Short for the Service Discovery Protocol layer, SDP allows for the discovery of services available from other devices over Bluetooth. Besides discovery, SDP allows applications to determine the technical characteristics of those services. SDP uses a request/response model for devices to communicate.

The threat is serious, but once again, it applies only to people using an Exynos version of one of the affected models. And once again, Google issued a patch earlier this month for Pixel users.

Until Samsung or Google says more, users of devices that remain vulnerable should (1) install all available security updates with a close eye out for one patching CVE-2023-24033, (2) turn off Wi-Fi calling, and (3) explore the settings menu of their specific model to see if it’s possible to turn off VoLTE. This post will be updated if either company responds with more useful information.





Source link

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • Click to email a link to a friend (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Tumblr (Opens in new window)
  • Click to share on Pinterest (Opens in new window)
  • Click to share on Telegram (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Like this:

Like Loading...

Related

Previous Post

US stocks close lower on the day. Nasdaq rises 4.4% this week. Dow has a small decline. | Forexlive

Next Post

Lance Reddick, actor in police dramas ‘The Wire’ and ‘Bosch,’ dies at 60

seelatestnews

seelatestnews

Next Post
Lance Reddick, actor in police dramas ‘The Wire’ and ‘Bosch,’ dies at 60

Lance Reddick, actor in police dramas ‘The Wire’ and ‘Bosch,’ dies at 60

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected test

  • 23.8k Followers
  • 99 Subscribers
  • Trending
  • Comments
  • Latest
Best red carpet fashion at the 2023 SAG Awards

Best red carpet fashion at the 2023 SAG Awards

February 27, 2023
Stocks making the biggest moves after hours: Zoom Video, Occidental Petroleum, Workday and more

Stocks making the biggest moves after hours: Zoom Video, Occidental Petroleum, Workday and more

February 27, 2023
Megan Fox Addressed Cheating Rumors In Her Relationship With Machine Gun Kelly In A New Instagram Statement

Megan Fox Addressed Cheating Rumors In Her Relationship With Machine Gun Kelly In A New Instagram Statement

February 19, 2023
Kate Middleton breaks down creative exercise routine as ‘busy mother’

Kate Middleton breaks down creative exercise routine as ‘busy mother’

January 20, 2023

Hello world!

1

Another Big Apartment Project Slated for Broad Ripple Company

0

Patricia Urquiola Coats Transparent Glas Tables for Livings

0

Ambrose Seeks Offers on Downtown Building for Apartments

0
18 Famous Women Who Either “Retired” From Dating Or Took A Looong Break To Be Single

18 Famous Women Who Either “Retired” From Dating Or Took A Looong Break To Be Single

April 2, 2023
Justin Sun In Talks To Sell Huobi Stake, Report Says

Justin Sun In Talks To Sell Huobi Stake, Report Says

April 2, 2023
Is Shadab Khan being replaced as vice-captain?

Is Shadab Khan being replaced as vice-captain?

April 2, 2023
‘Mahila Samman Savings Certificates’, New One-Time Investment Scheme For Girls & Women, Starts; Check Tenure, Interest, More

‘Mahila Samman Savings Certificates’, New One-Time Investment Scheme For Girls & Women, Starts; Check Tenure, Interest, More

April 2, 2023

Recent News

18 Famous Women Who Either “Retired” From Dating Or Took A Looong Break To Be Single

18 Famous Women Who Either “Retired” From Dating Or Took A Looong Break To Be Single

April 2, 2023
Justin Sun In Talks To Sell Huobi Stake, Report Says

Justin Sun In Talks To Sell Huobi Stake, Report Says

April 2, 2023
Is Shadab Khan being replaced as vice-captain?

Is Shadab Khan being replaced as vice-captain?

April 2, 2023
‘Mahila Samman Savings Certificates’, New One-Time Investment Scheme For Girls & Women, Starts; Check Tenure, Interest, More

‘Mahila Samman Savings Certificates’, New One-Time Investment Scheme For Girls & Women, Starts; Check Tenure, Interest, More

April 2, 2023

About Us

You Need it we have it . Here you will get and read the Current News, sports news, Historical News, health news, crypto news, Local News, Business News, fashion news, and trading news. Stay here and read your favorite news.

Browse by Category

  • Apps
  • Business
  • Crypto
  • Culture
  • Dubai Fashion
  • Entertainment
  • Forex
  • Freelancer
  • Gadget
  • Health & Fitness
  • India Fashion
  • Lifestyle
  • Mobile
  • Politics
  • Recipes
  • Review
  • Science
  • Sports
  • Sports
  • Tech News
  • Technology
  • Uncategorized
  • Video
  • World Fashion
  • World News

Recent News

18 Famous Women Who Either “Retired” From Dating Or Took A Looong Break To Be Single

18 Famous Women Who Either “Retired” From Dating Or Took A Looong Break To Be Single

April 2, 2023
Justin Sun In Talks To Sell Huobi Stake, Report Says

Justin Sun In Talks To Sell Huobi Stake, Report Says

April 2, 2023
Is Shadab Khan being replaced as vice-captain?

Is Shadab Khan being replaced as vice-captain?

April 2, 2023
‘Mahila Samman Savings Certificates’, New One-Time Investment Scheme For Girls & Women, Starts; Check Tenure, Interest, More

‘Mahila Samman Savings Certificates’, New One-Time Investment Scheme For Girls & Women, Starts; Check Tenure, Interest, More

April 2, 2023
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 seelatestnews |All Right Reversed

No Result
View All Result
  • Home
  • World News
  • Sports
  • Forex
  • Crypto
  • Tech News
  • Fashion
  • Entertainment
  • Lifestyle
  • More
    • Freelancer
    • Health & Fitness
    • Culture

© 2023 seelatestnews |All Right Reversed

Subscribe & see Our Latest News

%d bloggers like this: