Advanced SMS Phishing Attacks Targeting Android-Based Smartphones: Check Point

Check Point researchers said certain Samsung phones are the most vulnerable to this form of phishing attack.

Advertisement
By Indo-Asian News Service | Updated: 5 September 2019 18:57 IST
Highlights
  • Check Point said a variety of Android smartphones are affected
  • Certain Samsung phones are said to be most vulnerable
  • Samsung has issued a fix in its May security release

A security flaw in Samsung, LG, Sony, Huawei and other Android smartphones has been discovered that leaves users vulnerable to advanced SMS phishing attacks, Check Point Research -- the threat intelligence arm of cybersecurity firm Check Point Software Technologies Ltd. said on Thursday.

Researchers at the cybersecurity firm said certain Samsung phones are the most vulnerable to this form of phishing attack because they do not have an authenticity check for senders of Open Mobile Alliance Client Provisioning (OMA CP) messages.

Advertisement

"Given the popularity of Android devices, this is a critical vulnerability that must be addressed. Without a stronger form of authentication, it is easy for a malicious agent to launch a phishing attack through over-the-air (OTA) provisioning.

"When the user receives an OMA CP message, they have no way to discern whether it is from a trusted source. By clicking 'accept', they could very well be letting an attacker into their phone," Slava Makkaveev, Security Researcher, Check Point Software Technologies, said in a statement.

Advertisement

The affected Android phones use OTA provisioning, through which cellular network operators can deploy network-specific settings to a new phone joining their network.

However, researchers at Check Point found that the industry standard for OTA provisioning -- the OMA CP, includes limited authentication methods and remote agents can exploit this to pose as network operators and send deceptive OMA CP messages to users.

Advertisement

The message tricks users into accepting malicious settings that route their Internet traffic through a proxy server owned by the hacker.

The findings were disclosed to the affected vendors in March; Samsung included a fix addressing this phishing flaw in their Security Maintenance Release for May (SVE-2019-14073), LG released their fix in July (LVE-SMP-190006), and Huawei is planning to include UI fixes for OMA CP in the next generation of Mate series or P series smartphones.

Advertisement

However, Sony refused to acknowledge the vulnerability, stating that their devices follow the OMA CP specification.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Samsung, LG, Huawei, Sony, Check Point, SMS, Hack
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  2. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  3. Redmi Note 15 SE 5G Debuts in India With a Vegan Leather Finish: See Price
  4. Oppo Find X9 Ultra Runs Geekbench With These Key Specifications
  5. These Tech Companies Came Up With The Wildest April Fools Day 2026 Pranks
  6. These Three Pro Models Could Launch as Part of the Motorola Edge 70 Series
  7. Gadgets360 Awards 2026: Check Out Winners of India's Most Trusted Awards
  8. Samsung Galaxy A27 5G Visits Geekbench With This Older Snapdragon Chip
  9. NASA's Artemis II Crewed Lunar Mission Launched Successfully
  1. The House of the Spirits OTT Release Date: When and Where to Watch This Epic Family Drama Series?
  2. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Rear Camera: Price, Features
  3. Realme 16 5G Launched in India With 7,000mAh Battery, 50-Megapixel Selfie Camera: Price, Specifications 
  4. Redmi Note 15 SE 5G Launched in India With 5,800mAh Battery, Vegan Leather Finish: Price, Features
  5. Artemis II Launched: NASA’s First Crewed Mission in 50 Years Aims for the Moon
  6. Redmi K90 Ultra Listed on 3C Certification Database With 100W Fast Charging Support
  7. Motorola Edge 70 Series Said to Get Three New Pro Models; Motorola Razr 70 Colourways, Storage Leaked
  8. Oppo Find X9 Ultra Global Variant Listed on Geekbench Database With Key Specifications
  9. Google AI Pro Plan Upgraded With 5TB Cloud Storage Across Drive, Photos Apps at No Additional Cost
  10. Apple Issues Critical Update for Older iPhone Models Running iOS 18 to Address DarkSword Exploit
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.