Google Exposes Samsung Galaxy S6 Edge Vulnerabilities; Now Mostly Patched

Advertisement
By Manish Singh | Updated: 4 November 2015 11:44 IST

A number of flaws have been found in Samsung's Android handsets that allow an attacker to manipulate the privilege the device assigns to its apps, and access the victim's emails among other threats. Another vulnerability reported separately, makes it a child's play to bypass the Factory Reset Protection on Samsung phones and claim ownership of the device. Samsung has a patched majority of the vulnerabilities.

Google researchers found 11 vulnerabilities in Samsung's code used in the Galaxy S6 Edge that, if exploited, allow an attacker to target various aspects of the handset. Among those vulnerabilities, one is a path traversal vulnerability in Samsung's WifiHs20UtilityService. The service is programmed to scan for Zip archive file in a predefined location on the storage partition and extract it. The vulnerability can be exploited to make system files unpack in an unintended location.

Another notable vulnerability was found in the SecEmailCompose service that handles Samsung's email client. The vulnerability can be exploited to cause a user's email to be forwarded to another account. "It is a very noisy attack, as the forwarded emails show up in the user's sent folder, but it is still easy access to data that not even a privileged app should be able to access," the researchers explained.

Advertisement

Other vulnerabilities were found in the drivers of the Galaxy S6 Edge, and the company's handler that processes images. These can be exploited by an attacker to manipulate their privileges.

Advertisement

"Overall, we found a substantial number of high-severity issues, though there were some effective security measures on the device which slowed us down. The weak areas seemed to be device drivers and media processing. We found issues very quickly in these areas through fuzzing and code review. It was also surprising that we found the three logic issues that are trivial to exploit. These types of issues are especially concerning, as the time to find, exploit and use the issue is very short," the researchers wrote in a blog post.

The researchers noted that Samsung has patched the path traversal, the vulnerability that affected the email client, and six more flaws. It is not known when Samsung will fix the other three vulnerabilities, and whether it has rolled out the patch to the Galaxy S6 Edge handset yet.

Advertisement

A separate vulnerability demonstrated by security enthusiast RootJunky shows that it is surprisingly easy to bypass the Factory Reset Protection feature on the Galaxy Note 5 (and other Samsung-made Android handsets). By default, Google's Android software requires the registered Gmail address to be logged when a user reboots the device from recovery menu. The idea is to make it impossible for thieves to steal your phone, wipe it, and claim ownership of it.

Samsung has altered the process a little. It pulls up a file manager when the device is plugged into an external storage device. A user can bypass the security by opening a file and triggering Settings app. We've reached out to Samsung for comments.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  2. Nothing Phone 4a Pro Teaser Hints at the Presence of This Phone 3 Feature
  3. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  4. Here's When the Xiaomi 17T Could Make Its Way to India
  5. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  6. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  7. Samsung Galaxy A37, Galaxy A57 Get Better Geekbench Scores Ahead of Debut
  8. Xiaomi Targets Apple-Style Annual Chip Upgrades, Global Rollout Planned
  1. MWC 2026: Oppo, MediaTek Join Hands to Showcase New On-Device AI Capabilities for Future Smartphones
  2. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  3. Nubia Neo 5 GT With MediaTek Dimensity 7400 SoC Launched at MWC 2026: Price, Specifications
  4. OnePlus 16, iQOO 16, Redmi K100 Pro Max Tipped to Launch at Higher Prices This Year
  5. Google Play Announces New Android Policies With Expanded Billing Options, Eases Access to Third-Party App Stores
  6. Google's NotebookLM Upgraded With Cinematic Video Overviews Feature
  7. Infinix Note 60 Ultra Launched at MWC 2026 With Pininfarina Design, Satellite Calling: Price, Specifications
  8. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  9. OnePlus 15T Teasers Confirm Larger Battery, Faster Charging Speed and Higher IP Rating
  10. Nothing Phone 4a Pro Teaser Suggests Presence of Phone 3's Glyph Matrix Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.