Google Exposes Samsung Galaxy S6 Edge Vulnerabilities; Now Mostly Patched

Advertisement
By Manish Singh | Updated: 4 November 2015 11:44 IST

A number of flaws have been found in Samsung's Android handsets that allow an attacker to manipulate the privilege the device assigns to its apps, and access the victim's emails among other threats. Another vulnerability reported separately, makes it a child's play to bypass the Factory Reset Protection on Samsung phones and claim ownership of the device. Samsung has a patched majority of the vulnerabilities.

Google researchers found 11 vulnerabilities in Samsung's code used in the Galaxy S6 Edge that, if exploited, allow an attacker to target various aspects of the handset. Among those vulnerabilities, one is a path traversal vulnerability in Samsung's WifiHs20UtilityService. The service is programmed to scan for Zip archive file in a predefined location on the storage partition and extract it. The vulnerability can be exploited to make system files unpack in an unintended location.

Advertisement

Another notable vulnerability was found in the SecEmailCompose service that handles Samsung's email client. The vulnerability can be exploited to cause a user's email to be forwarded to another account. "It is a very noisy attack, as the forwarded emails show up in the user's sent folder, but it is still easy access to data that not even a privileged app should be able to access," the researchers explained.

Other vulnerabilities were found in the drivers of the Galaxy S6 Edge, and the company's handler that processes images. These can be exploited by an attacker to manipulate their privileges.

Advertisement

"Overall, we found a substantial number of high-severity issues, though there were some effective security measures on the device which slowed us down. The weak areas seemed to be device drivers and media processing. We found issues very quickly in these areas through fuzzing and code review. It was also surprising that we found the three logic issues that are trivial to exploit. These types of issues are especially concerning, as the time to find, exploit and use the issue is very short," the researchers wrote in a blog post.

The researchers noted that Samsung has patched the path traversal, the vulnerability that affected the email client, and six more flaws. It is not known when Samsung will fix the other three vulnerabilities, and whether it has rolled out the patch to the Galaxy S6 Edge handset yet.

Advertisement

A separate vulnerability demonstrated by security enthusiast RootJunky shows that it is surprisingly easy to bypass the Factory Reset Protection feature on the Galaxy Note 5 (and other Samsung-made Android handsets). By default, Google's Android software requires the registered Gmail address to be logged when a user reboots the device from recovery menu. The idea is to make it impossible for thieves to steal your phone, wipe it, and claim ownership of it.

Samsung has altered the process a little. It pulls up a file manager when the device is plugged into an external storage device. A user can bypass the security by opening a file and triggering Settings app. We've reached out to Samsung for comments.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 Power, X8 With 50-Megapixel Camera Debut in India: See Prices
  2. Lingverse iKairos Debuts as a Desktop Robot and Wearable AI Pendant
  3. Infinix Hot 70 Pro 5G Launched in India With These Features
  4. Oppo Find X10 Pro Max Leaked Images Reveal Two Colourways
  1. Oppo A7 Pro Launch Date Announced as Company Reveals Key Specifications, Design
  2. Vivo Announces Android 17-Based OriginOS 7 Launch Date; to Bring Liquid Glass-Like UI, Performance Upgrades
  3. US, UK Coordinate Efforts to Tackle Crypto Scams and Investment Fraud
  4. IFA 2026: Lingverse iKairos Debuts as a Desktop Robot and Wearable AI Pendant
  5. IFA 2026: Dreame Aqua20 Pro Ultra Roller X Complete Launched, Leaptic Cube Tags Along
  6. iQOO 16 to Launch Soon With a New Samsung Display, Similar Technology to Apple’s iPhone Ultra, Tipster Claims
  7. Oppo Find X10 Pro Max Leaked Images Reveal Two Colourways and Redesigned Triple-Rear Camera
  8. Apple’s First Foldable iPhone Could Cost More Than $2,000, New Report Claims
  9. Bitcoin Climbs Above $80,500 as Fed Rate Hike Bets Ease
  10. Apple’s ‘Surprise and Shine’ Event Could Bring New HomePod Models and Apple TV 4K
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.