Over 600 Million Samsung Mobile Devices Affected by SwiftKey Security Flaw: Report

Advertisement
By Ketan Pratap | Updated: 18 June 2015 16:36 IST
NowSecure, a Chicago-based mobile security company, has claimed that several Samsung Galaxy models are plagued with a keyboard security flaw that can allow an attacker remotely execute code as a system user.
(Also see: Samsung Says SwiftKey Keyboard Security Flaw Patch Coming in a Few Days)

According to the company, the security risk in over 600 million Samsung mobile devices have been caused due to the pre-installed Samsung IME keyboard app developed by SwiftKey, which cannot be uninstalled or disabled. The company has listed some of the impacted Samsung devices which include the flagships Galaxy S6, Galaxy S5, Galaxy S4, and even the Galaxy S4 mini. NowSecure claims that even when SwiftKey keyboard app is not used as the default keyboard - it can still be exploited.

The SwiftKey keyboard flaw can allow an attacker to remotely access sensors (including features such as GPS, camera, and microphone); secretly install malicious app without the user knowing and fiddle with how other apps function, or how the smartphone works. The security flaw can also allow an attacker to eavesdrop on incoming/ outgoing messages or voice calls while can allow access to personal data such as images and text messages.

The flaw was discovered by NowSecure mobile security researcher Ryan Welton and was reported to Samsung in December last year. The company also claims that Computer Emergency Response Teams (CERT) was also notified about the security flaw "given the magnitude of the issue."

Advertisement

The mobile security company suggests that Samsung started providing a patch to mobile network operators in early 2015; though it is unknown whether the carriers released the patch to the devices on their network.

Advertisement

Detailing how an attacker could access the vulnerability, NowSecure notes, "The attack vector for this vulnerability requires an attacker capable of modifying upstream traffic. The vulnerability is triggered automatically (no human interaction) on reboot as well as randomly when the application decides to update. This can include geographically proximate attacks such as rogue Wi-Fi access points or cellular base stations, or attacks from local users on a network, including ARP poisoning. Fully remote attacks are also feasible via DNS Hijacking, packet injection, a rogue router or ISP, etc."

NowSecure suggests users can avoid insecure Wi-Fi networks, use a different mobile device, or contact carriers for patch information and timing, to negate the risks.

Advertisement

In the meanwhile, SwiftKey in a emailed statement to NDTV Gadgets defended itself, saying the SwiftKey app available on Google Play and App Store has no such security flaw.

The company added that while SwiftKey supplies Samsung with the 'core technology' to power word predictions on its keyboards, it "appears the way this technology was integrated on Samsung devices introduced the security vulnerability." SwiftKey said it is working with "long-time partner" Samsung to resolve the issue.

Advertisement

The statement added that the vulnerability is difficult to exploit, and only possible if the Samsung device user is connected to a compromised network (such as a spoofed public Wi-Fi network) and the device is undergoing a language update at the same time. The hacker would also require the right tools specifically intended to gain access to the device.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Motorola Signature Could Cost in India
  2. Flipkart Reveals Deals on Phones For its Upcoming Sale: See Offers
  3. Redmi Note 15 Pro 5G India Variant Spied on Geekbench, Could Launch Soon
  4. Amazon Great Republic Day Sale 2026: Here Are the Top Deals on Laptops
  5. Here Are the Top 10 Deals on Smartphones During the Upcoming Amazon Sale
  6. Xiaomi 17 Max Battery Capacity, Chipset Details Revealed in New Leak
  1. PSLV-C62 Failure Marks India’s First Space Launch Setback of 2026
  2. A Massive Black Hole Starved Pablo’s Galaxy, Ending Its Star Formation
  3. Scientists Study 100 Possible Alien Signals as Arecibo’s Historic SETI Search Concludes
  4. Redmi Note 15 Pro 5G India Launch Seems Imminent After Smartphone Appears on Geekbench
  5. Battlefield 6 Season 2 Delayed to February as EA Extends Season 1
  6. CERT-In Urges Android Users to Update Smartphones After Google Patches Critical Dolby Vulnerability
  7. Apple Led Market as Global Smartphone Shipments Rose 2.3 Percent YoY in Q4 2025 Despite Growing Memory Shortage: IDC
  8. Red Magic 11 Air Design, Colour Options and Display Features Confirmed
  9. Motorola Signature Box Price in India, Launch Date Leaked Ahead of Arrival: Expected Specifications
  10. Dhandoraa Now Streaming on Prime Video: Know Everything About This Telugu Drama Film Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.