pwshub.com

Samsung phone users under attack, Google warns

A nasty bug in Samsung's mobile chips is being exploited by miscreants as part of an exploit chain to escalate privileges and then remotely execute arbitrary code, according to Google security researchers.

The use-after-free vulnerability is tracked as CVE-2024-44068, and it affects Samsung Exynos mobile processors versions 9820, 9825, 980, 990, 850, and W920. It received an 8.1 out of 10 CVSS severity rating, and Samsung, in its very brief security advisory, describes it as a high-severity flaw. The vendor patched the hole on October 7.

While the advisory doesn't make any mention of attackers abusing the vulnerability, according to Googlers Xingyu Jin and Clement Lecigene, someone(s) has already chained the flaw with other CVEs (those aren't listed) as part of an attack to execute code on people's phones.

The bug exists in the memory management and how the device driver sets up the page mapping, according to Lecigene, a member of Google's Threat Analysis Group, and Jin, a Google Devices and Services Security researcher who is credited with spotting the flaw and reporting it to Samsung.

"This 0-day exploit is part of an EoP chain," the duo said. "The actor is able to execute arbitrary code in a privileged cameraserver process. The exploit also renamed the process name itself to 'vendor.samsung.hardware.camera.provider@3.0-service,' probably for anti-forensic purposes."

  • Google splats device-hijacking exploited-in-the-wild Android kernel bug among others
  • What a coincidence. Spyware makers, Russia's Cozy Bear seem to share same exploits
  • The spyware business is booming despite government crackdowns
  • Millions of Android and iOS users at risk from hardcoded creds in popular apps

The Register reached out to Samsung for more information about the flaw and in-the-wild exploits, but did not immediately receive a response. We will update this story when we hear back. 

It's worth noting that Google TAG keeps a close eye on spyware and nation-state gangs abusing zero-days for espionage purposes. 

Considering that both of these threats frequently attack mobile devices to keep tabs on specific targets — Google tracked [PDF] 61 zero-days in the wild that specifically targeted end-user platforms and products in 2023 - we wouldn't be too surprised to hear that the exploit chain including CVE-2024-44068 ultimately deploys some snooping malware on people's phones. ®

Source: theregister.com

Related stories
3 weeks ago - If you're looking to upgrade your TV speakers, these are the best soundbars that will elevate your audio experience.
2 weeks ago - Though Prime Day is still a few days away, early discounts are already popping up. CNET's shopping experts have sifted through thousands of Amazon Prime Day deals to bring you the top savings.
2 weeks ago - Amazon's October Prime Day might not be here just yet, but with your own shopping expert sifting through thousands of early deals you won't miss any of the top savings.
2 weeks ago - With Amazon's October Prime Day just around the corner, your personal shopping expert is already sorting through thousands of early deals to ensure you catch all the best savings.
2 weeks ago - Amazon's October Prime Day sale is just around the corner! You can score some amazing early deals before they're gone for good.
Other stories
3 minutes ago - For some time, certain smartphones have offered locally-processed AI applications to edit and enhance photos, and with the introduction of Snapdragon X Elite SoCs and other NPU-enhanced processors, Microsoft has gradually started bringing...
24 minutes ago - Attacks on unprotected servers reach 'critical level' An unknown attacker is abusing exposed Docker Remote API servers to deploy perfctl cryptomining malware on victims' systems, according to Trend Micro researchers.…
31 minutes ago - Sleep better with these pillows designed for back sleepers, tested and reviewed by a CNET sleep expert.
31 minutes ago - Earlier this month, a woman appeared on my TikTok For You page who had flown all the way from the US to Thailand solely to see the internet-famous...
1 hour ago - We all love a deal from the local TJ's. But is your typical supermarket really more expensive than the quirky grocery store? We crunched some numbers to find out.