• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Saturday, December 9, 2023
Flyy News
No Result
View All Result
  • Home
  • World
  • Business
  • Entertainment
  • Health
  • Food
  • Politics
  • Tech
  • Science
  • Travel
  • Fashion
  • Lifestyle
  • Home
  • World
  • Business
  • Entertainment
  • Health
  • Food
  • Politics
  • Tech
  • Science
  • Travel
  • Fashion
  • Lifestyle
No Result
View All Result
Flyy News
No Result
View All Result
Home Tech

Google tells users of some Android phones: Nuke voice calling to avoid infection

flyynews by flyynews
March 19, 2023
in Tech
0
Google tells users of some Android phones: Nuke voice calling to avoid infection
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


Images of the Samsung Galaxy S21, which runs with an Exynos chipset.
Enlarge / Images of the Samsung Galaxy S21, which runs with an Exynos chipset.

Samsung

Google is urging owners of certain Android phones to take urgent action to protect themselves from critical vulnerabilities that give skilled hackers the ability to surreptitiously compromise their devices by making a specially crafted call to their number.  It’s not clear if all actions urged are even possible, however, and even if they are, the measures will neuter devices of most voice-calling capabilities.

The vulnerability affects Android devices that use the Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5123 chipsets made by Samsung’s semiconductor division. Vulnerable devices include the Pixel 6 and 7, international versions of the Samsung Galaxy S22, various mid-range Samsung phones, the Galaxy Watch 4 and 5, and cars with the Exynos Auto T5123 chip. These devices are ONLY vulnerable if they run the Exynos chipset, which includes the baseband that processes signals for voice calls. The US version of the Galaxy S22 runs a Qualcomm Snapdragon chip.

A bug tracked as CVE-2023-24033 and three others that have yet to receive a CVE designation make it possible for hackers to execute malicious code, Google’s Project Zero vulnerability team reported on Thursday. Code-execution bugs in the baseband can be especially critical because the chips are endowed with root-level system privileges to ensure voice calls work reliably.

“Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number,” Project Zero’s Tim Willis wrote. “With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.”

Advertisement

Earlier this month, Google released a patch for vulnerable Pixel 7 models, but fixes for Pixel 6 models have yet to be delivered to many, if not all, users (the Project Zero post incorrectly states otherwise). Samsung has released an update patching CVE-2023-24033, but it has not yet been delivered to end users. There’s no indication Samsung has issued patches for the other three critical vulnerabilities. Until vulnerable devices are patched, they remain vulnerable to attacks that give access at the deepest level possible.

READ ALSO

Shop the QVC Holiday Gift-A-Thon This Weekend to Prepare for the Holidays

The EU Just Passed Sweeping New Rules to Regulate AI

The threat prompted Willis to put this advice at the very top of Thursday’s post:

Until security updates are available, users who wish to protect themselves from the baseband remote code execution vulnerabilities in Samsung’s Exynos chipsets can turn off Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings. Turning off these settings will remove the exploitation risk of these vulnerabilities.

The problem is, it’s not entirely clear that it’s possible to turn off VoLTE, at least on many models. A screenshot one S22 user posted to Reddit last year shows that the option to turn off VoLTE is grayed out. While that user’s S22 was running a Snapdragon chip, the experience for users of Exynos-based phones is likely the same.

And even if it is possible to turn off VoLTE, doing so in conjunction with turning off Wi-Fi turns phones into little more than tiny tablets running Android. VoLTE came into widespread use a few years ago, and since then most carriers in North America have stopped supporting older 3G and 2G frequencies.

Samsung representatives said in an email that the company in March released security patches for five of six vulnerabilities that “may potentially impact select Galaxy devices” and will patch the sixth flaw next month. The email didn’t answer questions asking if any of the patches are available to end users now or whether it’s possible to turn off VoLTE. The email also failed to make clear that patches have yet to be delivered to end users.

Advertisement

A Google representative, meanwhile, declined to provide the specific steps for carrying out the advice in the Project Zero writeup. That means Pixel 6 users have no actionable mitigation steps while they wait an updated for their devices. Readers who figure out a way are invited to explain the process (with screenshots, if possible) in the comments section.

Because of the severity of the bugs and the ease of exploitation by skilled hackers, Thursday’s post omitted technical details. In its product security update page, Samsung described CVE-2023-24033 as a “memory corruption when processing SDP attribute accept-type.”

“The baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to a denial of service or code execution in Samsung Baseband Modem,” the advisory added. “Users can disable WiFi calling and VoLTE to mitigate the impact of this vulnerability.”

Short for the Session Description Protocol, SDP is a mechanism for establishing a multimedia session between two entities. Its main use is supporting streaming VoIP calls and video conferencing. SDP uses a offer/answer model in which one party advertises a description of a session and the other party answers with the desired parameters.

The threat is serious, but once again, it applies only to people using an Exynos version of one of the affected models.

Until Samsung or Google says more, users of devices that remain vulnerable should (1) install all available security updates with a close eye out for one patching CVE-2023-24033, (2) turn off Wi-Fi calling, and (3) explore the settings menu of their specific model to see if it’s possible to turn off VoLTE. This post will be updated if either company responds with more useful information.

Post updated to correct the definition of SDP.





Source_link

Related Posts

Shop the QVC Holiday Gift-A-Thon This Weekend to Prepare for the Holidays
Tech

Shop the QVC Holiday Gift-A-Thon This Weekend to Prepare for the Holidays

December 9, 2023
The EU Just Passed Sweeping New Rules to Regulate AI
Tech

The EU Just Passed Sweeping New Rules to Regulate AI

December 9, 2023
EU agrees to landmark rules on artificial intelligence
Tech

EU agrees to landmark rules on artificial intelligence

December 9, 2023
5 things we didn’t put on our 2024 list of 10 Breakthrough Technologies
Tech

5 things we didn’t put on our 2024 list of 10 Breakthrough Technologies

December 8, 2023
The animated VTuber Ironmouse won Content Creator of the Year at the Game Awards
Tech

The animated VTuber Ironmouse won Content Creator of the Year at the Game Awards

December 8, 2023
Proton Drive brings end-to-end encrypted photo backups to Android
Tech

Proton Drive brings end-to-end encrypted photo backups to Android

December 8, 2023
Next Post
S&P cuts First Republic deeper into junk, says $30 billion infusion may not solve problems

S&P cuts First Republic deeper into junk, says $30 billion infusion may not solve problems

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Angel -Dave Curl – Official Music Video 2022

Angel -Dave Curl – Official Music Video 2022

November 17, 2022
Worker retention statistics that may marvel you

Worker retention statistics that may marvel you

September 16, 2022
Wanaka – Another Spoon Official Music Video

Wanaka – Another Spoon Official Music Video

October 15, 2022
Proud By Cytonic Rhymes – Official Music 2022

Proud By Cytonic Rhymes – Official Music 2022

November 25, 2022
Sweet Bennie Ray – Whole Lot (Official Music Video)

Sweet Bennie Ray – Whole Lot (Official Music Video)

December 22, 2022

About Us

Welcome to Flyy News The goal of Flyy News is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Follow us

Categories

  • Business
  • Entertainment
  • Fashion
  • Food
  • Gaming
  • Health
  • Lifestyle
  • Politics
  • Reviews
  • Science
  • Tech
  • Travel
  • World

Site Links

  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Recent News

  • DEVELOPING: Elon Musk Considers Reinstating Alex Jones on X | The Gateway Pundit
  • The First Crispr Medicine Is Now Approved in the US
  • The daunting challenges confronting Eskom’s new CEO
  • 53+ Ways to Give Experience Gifts Instead of Stuff This Year

Copyright © 2022 Flyynews.com | All Rights Reserved.

No Result
View All Result
  • Home
  • World
  • Business
  • Entertainment
  • Health
  • Food
  • Politics
  • Tech
  • Science
  • Travel
  • Fashion
  • Lifestyle

Copyright © 2022 Flyynews.com | All Rights Reserved.

What Are Cookies
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT