Samsung 'Find My Mobile' Exploit Allegedly Lets Attackers Remotely Lock Your Phone

Advertisement
By NDTV Correspondent | Updated: 28 October 2014 18:55 IST

An Egyptian security researcher has allegedly found a vulnerability in Samsung's Find My Mobile service that enables unauthorised individuals to send remote lock, unlock, and ring commands to Samsung devices that support the service.

Also reported by the National Institute of Standards and Technology (NIST) in the US on its National Vulnerability Database (NVD), the Find My Mobile vulnerability has been given a high-severity rating at 7.8, with an exploitability sub-score of 10.0, due to its network exploitable nature, low access complexity, no authentication requirement, and disruption potential.

The NIST vulnerability summary states, "The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic."

Samsung has not yet responded to the reports of the Find My Mobile vulnerability, and is expected to issue an update to its Galaxy Apps suite to fix the problem.

Advertisement

Two proof-of-concept videos have been uploaded to YouTube by Egyptian security researcher Mohamed A. Baset (@SymbianSyMoh) that show the vulnerability being exploited with cross-site request forgery (CSRF) attacks, where he is able to insert scripts into Find My Mobile fields via the Web interface to force the service to lock, unlock, and ring a linked Samsung smartphone.

Notably, the CSRF attack used by Baset is able to lock a Samsung smartphone with a "specific device lock code" set by the attacker, essentially causing a denial of service to the smartphone owner. Baset was also able to set a custom message in each case (locking, unlocking, ringing).

Advertisement

For now, it is being recommended that Samsung smartphone users turn off the Find My Mobile service, which as Computerworld notes is automatically enabled once a user registers for a Samsung account, or opens Galaxy Apps or Samsung Hub.

Samsung

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S25 Price Increased by Up to Rs. 12,000
  2. OnePlus 16 Specifications Leaked Online
  3. GTA 6 Gameplay Has Leaked Ahead of Planned Netflix Premiere
  4. Realme P4s 5G to Launch in India on August 26 With These Features
  5. iQOO Neo 11 Ultra Debuts With Dimensity 9500M Chip
  6. BGMI Lite Pre-Registrations for Android Users to Open on August 25
  7. Poco M8x 5G Will Launch in India in These Colour Options
  8. Vivo's OriginOS 7 Leak Reveals New Glass Styles, Control Centre Tweaks
  1. PlayStation Pulse Elevate Wireless Speakers Price, Features Revealed Ahead of November 12 Launch
  2. Telegram Users Could Get Personalised .gram Domains if ICANN Approves
  3. Bybit Says It Prevented Over $700 Million in Losses After $1.46 Billion Hack
  4. Samsung Galaxy S25 Price Hiked in India by Up to Rs. 12,000: Here’s How Much It Costs Now
  5. Control Resonant's Physical Release Delayed to October as Game Goes Gold
  6. Vivo's Android-17 Based OriginOS 7 Could Get Liquid Glass UI and More Customisation Options
  7. Nexo Australia Begins Offering Credit Lines Against Cryptocurrency Collateral
  8. WhatsApp Could Soon Let You Expand Photos to 9:16 Format on Android Using Meta AI
  9. Poco M8x 5G Colour Options, Durability Details and More Announced Ahead of India Launch
  10. OnePlus 16 Display Details Again Leaked Online; Tipped to Feature ColorOS 17
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.