Over 600 Million Samsung Mobile Devices Affected by SwiftKey Security Flaw: Report

Advertisement
By Ketan Pratap | Updated: 18 June 2015 16:36 IST
NowSecure, a Chicago-based mobile security company, has claimed that several Samsung Galaxy models are plagued with a keyboard security flaw that can allow an attacker remotely execute code as a system user.
(Also see: Samsung Says SwiftKey Keyboard Security Flaw Patch Coming in a Few Days)

According to the company, the security risk in over 600 million Samsung mobile devices have been caused due to the pre-installed Samsung IME keyboard app developed by SwiftKey, which cannot be uninstalled or disabled. The company has listed some of the impacted Samsung devices which include the flagships Galaxy S6, Galaxy S5, Galaxy S4, and even the Galaxy S4 mini. NowSecure claims that even when SwiftKey keyboard app is not used as the default keyboard - it can still be exploited.

The SwiftKey keyboard flaw can allow an attacker to remotely access sensors (including features such as GPS, camera, and microphone); secretly install malicious app without the user knowing and fiddle with how other apps function, or how the smartphone works. The security flaw can also allow an attacker to eavesdrop on incoming/ outgoing messages or voice calls while can allow access to personal data such as images and text messages.

The flaw was discovered by NowSecure mobile security researcher Ryan Welton and was reported to Samsung in December last year. The company also claims that Computer Emergency Response Teams (CERT) was also notified about the security flaw "given the magnitude of the issue."

Advertisement

The mobile security company suggests that Samsung started providing a patch to mobile network operators in early 2015; though it is unknown whether the carriers released the patch to the devices on their network.

Advertisement

Detailing how an attacker could access the vulnerability, NowSecure notes, "The attack vector for this vulnerability requires an attacker capable of modifying upstream traffic. The vulnerability is triggered automatically (no human interaction) on reboot as well as randomly when the application decides to update. This can include geographically proximate attacks such as rogue Wi-Fi access points or cellular base stations, or attacks from local users on a network, including ARP poisoning. Fully remote attacks are also feasible via DNS Hijacking, packet injection, a rogue router or ISP, etc."

NowSecure suggests users can avoid insecure Wi-Fi networks, use a different mobile device, or contact carriers for patch information and timing, to negate the risks.

Advertisement

In the meanwhile, SwiftKey in a emailed statement to NDTV Gadgets defended itself, saying the SwiftKey app available on Google Play and App Store has no such security flaw.

The company added that while SwiftKey supplies Samsung with the 'core technology' to power word predictions on its keyboards, it "appears the way this technology was integrated on Samsung devices introduced the security vulnerability." SwiftKey said it is working with "long-time partner" Samsung to resolve the issue.

Advertisement

The statement added that the vulnerability is difficult to exploit, and only possible if the Samsung device user is connected to a compromised network (such as a spoofed public Wi-Fi network) and the device is undergoing a language update at the same time. The hacker would also require the right tools specifically intended to gain access to the device.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  2. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  3. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  4. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  5. You Can Now Use OpenAI's Codex App on Windows
  6. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  7. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  8. Samsung Galaxy A47 5G, Galaxy A57 5G Specifications Leak Ahead of Launch
  9. Nothing Phone 4a First Impressions
  10. WhatsApp Plus Could Soon Let You Pay to Access These Features
  1. Samsung Galaxy A37 5G and Galaxy A57 5G Specifications Reportedly Leaked in Full Ahead of Launch
  2. ISS Crew Prepares to Send Japan’s HTV-X1 Cargo Spacecraft Back to Earth After Four Months
  3. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  4. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  5. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  6. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  7. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  8. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  9. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  10. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.