-

Kryptowire Identifies High Risk Security Vulnerability in Samsung Devices Running Android

Vulnerability enabled untrusted apps to hijack phones and any other Android systems, gaining unauthorized access to privileged data and capabilities

MCLEAN, Va.--(BUSINESS WIRE)--Kryptowire Inc., a mobile security and privacy solutions company, today announced it identified a serious security vulnerability (CVE-2022-22292) in Samsung devices running Android versions 9 through 12. The vulnerability, discovered using Kryptowire Mobile Application Security Testing (MAST), allowed local applications to mimic system-level activity and “hijack” critical protected functionality. The vulnerability could give attackers the ability to initiate a factory reset (i.e., deleting all user data), make phone calls (including to emergency numbers such as 911), install/uninstall apps, weaken HTTPS security by installing arbitrary root certificates, all from untrusted apps running in the background and without end-user approval.

“Ever think someone else has access to your phone? Unfortunately, you may be right,” said Alex Lisle, CTO of Kryptowire. “Mobile applications are becoming the primary point of personal and professional activity, representing an increasingly attractive target for bad actors.”

The CVE-2022-22292 vulnerability was disclosed to Samsung on November 27, 2021 and given a “High” severity rating by Samsung. Samsung patched the vulnerability in February 2022 as part of its ongoing Security Maintenance Release (SMR) process. The vulnerability resides in the pre-installed Phone app that executes with system privileges on Samsung devices running Android 9 through 12. The Phone app has an insecure component which allows local apps to perform privileged operations without user authorization.

To ensure end users and businesses deliver customers peace of mind, automated mobile security scanning must become common practice. As points of vulnerability and associated threats increase, a proactive security posture represents the most reliable way to protect personal and corporate data from bad actors – criminals who stand increasingly more to gain, and whose methods are becoming increasingly sophisticated.

Accordingly, developers and enterprises responsible for app development and security should consider implementing an appropriate solution before a major incident occurs, instead of as a reactive measure.

For more details on the finding visit: https://www.kryptowire.com/blog/start-arbitrary-activity-app-components-as-the-system-user-vulnerability-affecting-samsung-android-devices/

About Kryptowire MAST

Kryptowire Mobile Application Security Testing (MAST) allows app managers to scan for security, privacy, and compliance vulnerabilities using an automatic, cloud-based solution. In 2021, Kryptowire scanned over 3 billion lines of code across 70,000 applications, discovering over 500 vulnerabilities affecting approximately 2 billion devices.

About Kryptowire Inc.

Kryptowire is a leader in cloud-based mobile security and privacy solutions, delivering organizations and end-users the peace of mind that comes with intrusion-free mobile security. We enable organizations to scan mobile devices and applications for security, compliance, and other vulnerabilities with no source code access, saving time and costs with zero intrusion into end user privacy. Our mission is to make world-class mobile security more accessible and valuable for businesses and communities around the world.

Please visit www.kryptowire.com or connect with us on LinkedIn and Twitter (@kryptowire) for more information.

Contacts

Media Contact
Jaime Le
jle@kryptowire.com

Kryptowire Inc.


Release Versions

Contacts

Media Contact
Jaime Le
jle@kryptowire.com

More News From Kryptowire Inc.

Quokka Publishes the Shopping App “Nice List” for the 2022 Holiday Season

MCLEAN, Va.--(BUSINESS WIRE)--Quokka, Inc., a mobile security and privacy solutions company, today announced the publication of its 2022 Mobile Apps Nice List showcasing what it considers the most trustworthy Android mobile apps available to end-users this holiday season. Results of Quokka testing reveal Society6, Madewell, Lucky Supermarket, Brad’s Deals and Stripe Dashboard appear to be the safest shopping apps and pose the lowest threat to end-users privacy and digital safety. According to I...

Quokka Announces Integration with GitLab Inc. Enabling Developers to Deliver High-Quality, Secure Mobile Apps to Market Faster

MCLEAN, Va.--(BUSINESS WIRE)--Quokka, Inc., a mobile security and privacy solutions company, today announced it has joined GitLab Inc.’s global partner program. Quokka’s industry-leading Mobile Application Security Testing solution, Q-MAST, is available to developers on GitLab’s One DevOps Platform allowing mobile app developers to test their apps during the development process to help ensure they are delivering secure mobile applications with the requisite security standards and quality. To me...

Kryptowire Announces Rebrand to Quokka

MCLEAN, Va.--(BUSINESS WIRE)--Quokka, Inc., a mobile security and privacy company, today announced its official rebrand from Kryptowire to Quokka. Alongside the rebrand comes a refreshed mission to transform the world of digital security beyond distrust and provide proactive mobile security that makes you and your customers, organization, and employees feel safe and secure. Aiming to be the antithesis of the security industry focused on living in fear, Quokka delivers ahead-of-the-curve securit...
Back to Newsroom