Samsung SmartThings Vulnerability Lets Attackers Access Your Devices; Fix Released

Advertisement
By Ketan Pratap | Updated: 5 May 2016 19:00 IST
Highlights
  • Researchers reported two design flaws in the SmartThings platform.
  • SmartThings has rolled out fixes for the security vulnerabilities.
  • Samsung bought the home automation startup SmartThings in 2014.
A research team from the University of Michigan and Microsoft Research has discovered a vulnerability in Samsung's SmartThings platform that can allow attackers to perform unauthorised activities through a malicious app. The vulnerability is major considering that it can allow an attacker to control a broad range of personal devices under SmartThings such as motion sensors, fire alarms, and door locks.

SamsungSmartThings however has released number of updates that are claimed to protect SmartThings users against the potential vulnerabilities reported by the research team. "Over the past several weeks, we have been working with this research team and have already implemented a number of updates to further protect against the potential vulnerabilities disclosed in the report. It is important to note that none of the vulnerabilities described have affected any of our customers thanks to the SmartApp approval processes that we have in place," said Alex Hawkinson Founder and CEO, SmartThings.

In a published report, the researchers explain how they exploited the vulnerability, "SmartThings hosts the application runtime on a proprietary, closed-source cloud backend, making scrutiny challenging. We overcame the challenge with a static source code analysis of 499 SmartThings apps (called SmartApps) and 132 device handlers, and carefully crafted test cases that revealed many undocumented features of the platform."

The report highlighted two design flaws that can allow attackers to take advantage of a privilege problem in SmartApps. First the SmartApp is granted full access to a device even if it just requires only limited access to the device, and secondly SmartThings event subsystem does not sufficiently protect events that carry sensitive information such as lock codes. "Our analysis reveals that over 55 percent of SmartApps in the store are over privileged due to the capabilities being too coarse-grained," added the report.

Advertisement

To check the vulnerability in SmartThings, researchers exploited design flaws and constructed an attack. "Four proof-of-concept attacks that: (1) secretly planted door lock codes; (2) stole existing door lock codes; (3) disabled vacation mode of the home; and (4) induced a fake fire alarm. We conclude the paper with security lessons for the design of emerging smart home programming frameworks," added the report. The researchers also demonstrated the exploit in a video.

Advertisement

The researchers also conducted a survey with 22 SmartThings users regarding the door lock pin-code snooping attack. "Our survey result suggests that most of our participants have limited understanding of security and privacy risks of the SmartThings platform - over 70 percent of our participants responded that they would be interested in installing a battery monitoring app and would give it access to a door lock. Only 14 percent of our participants reported that the battery monitor SmartApp could perform a door lock pin-code snooping attack," added the report.

Samsung SmartThings acknowledged the team of researchers and adds that it regularly performs security checks of its SmartThings system and also engages with professional third-party security experts to find any potential vulnerabilities in the platform.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  3. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  4. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  5. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  6. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  9. FaceTime, Snapchat Video Calls Have Reportedly Been Blocked in Russia
  10. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  1. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  2. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  3. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  4. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  5. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  6. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  7. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  8. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  9. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  10. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.