The hack was demonstrated at the Ekoparty security conference recently and can be triggered using a USSD code sent via NFC, QR code, a website.
At this point, the hack was found working on Samsung Galaxy S III, Galaxy Beam, Galaxy S Advance, Galaxy Ace and Galaxy S II, all popular Samsung smartphones.
(Update: Samsung has released a patch for Galaxy S III, though fate of other phones remains unclear)
As the malicious code does not work on Galaxy Nexus, which runs on stock Android, the Touchwiz running devices seems to be affected. Stock Android shows the code in the dialler but does not run it automatically, while the USSD code executes automatically on Touchwiz featuring devices.
Another concern surrounding the hack is another piece of code which allows disabling the SIM card currently in the phone. This way, with a single attack, the entire Samsung phone can be wiped and the SIM card killed.
The phone users do see the process happening in front of them, but pressing back or any other key has no impact on the process. Removing the battery during the processor is also likely to cripple the phone.
Samsung is yet to issue a statement on the matter.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.
Samsung Galaxy Watch 9 (44mm, LTE)
Starts from ₹44,999
Samsung Galaxy Watch 9 (40mm, LTE)
Starts from ₹37,999
Samsung Galaxy Watch 9 (40mm)
Starts from ₹37,999
Haier M70 Mini LED 65-inch
Starts from ₹74,990
CMF Buds Neo True Wireless Stereo (TWS) Earphones
Starts from ₹2,199
Xiaomi TV FX Mini LED 65
Starts from ₹64,999
IFA 2026: Nvidia RTX Spark PCs, Local AI Tools Announced With October Launch Planned
Luna Band Now Available Globally: Check Price in India, Specifications and Features