Over 600 Million Samsung Mobile Devices Affected by SwiftKey Security Flaw: Report

Advertisement
By Ketan Pratap | Updated: 18 June 2015 16:36 IST
NowSecure, a Chicago-based mobile security company, has claimed that several Samsung Galaxy models are plagued with a keyboard security flaw that can allow an attacker remotely execute code as a system user.
(Also see: Samsung Says SwiftKey Keyboard Security Flaw Patch Coming in a Few Days)

According to the company, the security risk in over 600 million Samsung mobile devices have been caused due to the pre-installed Samsung IME keyboard app developed by SwiftKey, which cannot be uninstalled or disabled. The company has listed some of the impacted Samsung devices which include the flagships Galaxy S6, Galaxy S5, Galaxy S4, and even the Galaxy S4 mini. NowSecure claims that even when SwiftKey keyboard app is not used as the default keyboard - it can still be exploited.

The SwiftKey keyboard flaw can allow an attacker to remotely access sensors (including features such as GPS, camera, and microphone); secretly install malicious app without the user knowing and fiddle with how other apps function, or how the smartphone works. The security flaw can also allow an attacker to eavesdrop on incoming/ outgoing messages or voice calls while can allow access to personal data such as images and text messages.

Advertisement

The flaw was discovered by NowSecure mobile security researcher Ryan Welton and was reported to Samsung in December last year. The company also claims that Computer Emergency Response Teams (CERT) was also notified about the security flaw "given the magnitude of the issue."

The mobile security company suggests that Samsung started providing a patch to mobile network operators in early 2015; though it is unknown whether the carriers released the patch to the devices on their network.

Advertisement

Detailing how an attacker could access the vulnerability, NowSecure notes, "The attack vector for this vulnerability requires an attacker capable of modifying upstream traffic. The vulnerability is triggered automatically (no human interaction) on reboot as well as randomly when the application decides to update. This can include geographically proximate attacks such as rogue Wi-Fi access points or cellular base stations, or attacks from local users on a network, including ARP poisoning. Fully remote attacks are also feasible via DNS Hijacking, packet injection, a rogue router or ISP, etc."

NowSecure suggests users can avoid insecure Wi-Fi networks, use a different mobile device, or contact carriers for patch information and timing, to negate the risks.

Advertisement

In the meanwhile, SwiftKey in a emailed statement to NDTV Gadgets defended itself, saying the SwiftKey app available on Google Play and App Store has no such security flaw.

The company added that while SwiftKey supplies Samsung with the 'core technology' to power word predictions on its keyboards, it "appears the way this technology was integrated on Samsung devices introduced the security vulnerability." SwiftKey said it is working with "long-time partner" Samsung to resolve the issue.

Advertisement

The statement added that the vulnerability is difficult to exploit, and only possible if the Samsung device user is connected to a compromised network (such as a spoofed public Wi-Fi network) and the device is undergoing a language update at the same time. The hacker would also require the right tools specifically intended to gain access to the device.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  2. Vivo X300 FE Roundup: Expected Price in India, Specifications
  3. Redmi K90 Max Debuts With Active Cooling Fan, 8,550mAh Battery: See Price
  4. GeForce Now Review:  Is Nvidia's High-End Cloud Gaming Service For You?
  5. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  6. Dyson Launches Supersonic Travel as Smaller, Lighter Hair Dryer
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.