Samsung Smartphones Since 2014 Affected by Critical Zero-Click Bug That Allows Remote Code Execution

The Samsung zero-click vulnerability resides in how the company's Android system interacts with the custom Qmage format.

Advertisement
By Abhik Sengupta | Updated: 7 May 2020 16:05 IST
Highlights
  • Samsung listed the vulnerability as "critical"
  • The vulnerability can reveal call logs, contacts, and more
  • It is uncertain whether the fix will be rolled out to all Samsung devices
Samsung Smartphones Since 2014 Affected by Critical Zero-Click Bug That Allows Remote Code Execution

Samsung phones recently started receiving May security patch

Samsung started rolling out the May 2020 Security Patch last week. The security patch fixes a "critical" remote code execution (RCE) bug plaguing all Samsung mobiles sold since 2014. The security flaw resides in Samsung devices' handling of the custom Qmage image format (.qmg) that is processed by Android's graphics library called Skia. This security flaw can be exploited in a zero-click scenario, which means that it can work without users' knowledge or without any kind of interaction with the device. Meanwhile, Samsung has acknowledged the security issue and its May security update contains the fix. It is uncertain whether the fix will be rolled out to all affected devices however, and we've reached out to the company for clarity on eligible devices.

What is the security flaw?

The security flaw resides with how Samsung devices interact with the Qmage image format was pointed by Mateusz Jurczyk, a security researcher with Google's Project Zero bug-hunting team and was first reported by ZDNet. According to Jurczyk, once a Samsung user receives an image file via Samsung Messages app, Android redirects all images to the Skia library for processing. However, the image files with .qmg format can be exploited as it can reveal the position of the Skia library in the phone's memory. The research further states that it requires up to 300 MMS messages to probe and bypass Android's Address Space Layout Randomisation (ASLR) protection. The whole process of locating the Skia library typically takes around 100 minutes.

What happens after the Skia library is located?

As per Jurczyk, once the Skia library is traced via the Qmage file (in this case through files received on Samsung Messages app), the hacker can execute codes without user's interaction with the device. As for what the hacker gains here, Jurczyk indicates that the attacker gains full access to a variety of personal user information including call logs, contacts, microphone, storage, SMS messages, etc.

Advertisement

"After reporting the crashes, I spent several weeks working on a 0-click MMS exploit proof-of-concept for one of the vulnerabilities. I managed to achieve this goal with a Samsung Galaxy Note 10+ phone running Android 10." The process of locating the Skia library on the Samsung device was also demonstrated in a video by the security researcher.

Advertisement

Samsung smartphones started supporting the custom Qmage format on all devices released since late 2014. Samsung is said to be the only manufacturer affected by the bug, as it is reportedly the only one that modified the Android OS on its devices to support the Qmage format, developed by South Korean firm Quramsoft.

What is Samsung saying?

Although Samsung has not released any statement about the Qmage security flaw, the company is, however, rolling out updates to fix the problem. Recently, Samsung Galaxy S20 Series received the May 2020 security patch that fixes the zero-click vulnerability dubbed as SVE-2020-16747. The bug can be found on the Samsung security bulletin that has listed it as a "critical" issue. It describes it as "A possible memory overwrite vulnerability in Quram qmg library allows possible remote arbitrary code execution." As mentioned, it is uncertain which devices will receive fix, and we've reached out for clarity on this front.


Is Mi 10 an expensive OnePlus 8 or a budget budget S20 Ultra? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Play Ultra 5G to Launch in India on August 20 With These Features
  2. Samsung Galaxy S26 Pro May Come With a 6.27-inch Screen, 4,300mAh Battery
  3. Google Will Now Let You Find the Cheapest Flights for Your Trips With AI
  4. Xiaomi 16 Series to Debut With 'Significant Changes' to Product Positioning
  5. BSNL 4G Services Launched in Delhi; Anti-Spam, Brings Anti-Smishing to All
  6. Oppo K13 Turbo With Built-in Cooling Fan Goes on Sale in India: See Price
  7. Redmi Note 15 Pro+ Launch Date, Design, Key Features Confirmed
  8. Asus ROG Xbox Ally Briefly Listed on This Website Ahead of Launch
  9. Samsung Galaxy A17 5G Price Leaked: Here's How Much It Might Cost in India
  1. Samsung Galaxy A17 5G Price in India Leaked, Could Launch Soon
  2. Redmi Note 15 Pro+ Launch Date Announced; Company Reveals Design, Key Features
  3. BSNL 4G Services Rolled Out in Delhi; Anti-Spam and Smishing Protection Expands to All Users
  4. Apple to Reportedly Witness More Senior Executives Exit Amid Ongoing Succession Changes
  5. Asus ROG Xbox Ally Briefly Listed on Amazon Ahead of Imminent Launch Date Announcement
  6. Xiaomi 16 Series to Launch in China With 'Significant Changes' to Product Positioning
  7. Samsung Galaxy S26 Pro Tipped to Come With a 6.27-inch Screen and 4,300mAh Battery
  8. Samsung to Expand Manufacturing of Advanced Tech Devices in India, Says Ashwini Vaishnaw
  9. Oppo K13 Turbo With MediaTek Dimensity 8450 SoC Goes on Sale in India: Price, Offers
  10. Apple Watch With New Sensors, Major Redesign to Launch in 2026: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.