Samsung Says 'Find My Mobile' Vulnerability Was Fixed Last Month

Advertisement
By NDTV Correspondent | Updated: 5 November 2014 19:17 IST
Samsung has responded to reports from last month about a vulnerability in its Find My Mobile service, specifically that which allowed unauthorised individuals to remotely lock, unlock, and ring Samsung devices.

The Find My Mobile vulnerability was reported by the National Institute of Standards and Technology (NIST) in the US on its National Vulnerability Database (NVD), which gave it a high-severity rating at 7.8, and an exploitability sub-score of 10.0 due to its network exploitable nature, low access complexity, no authentication requirement, and disruption potential.

The Samsung Find My Mobile vulnerability was also reported by Egyptian security researcher Mohamed A. Baset (@SymbianSyMoh), who also uploaded two videos showing the vulnerability being exploited with cross-site request forgery (CSRF) attacks. Baset said he was able to insert scripts into Find My Mobile fields via the Web interface to force the service to lock, unlock, and ring a linked Samsung smartphone.

Samsung responded to the reports on its global blog in a post titled, 'Samsung's Find My Mobile service is safe'. The South Korean consumer electronics giant said the "reported issue in Find My Mobile was fixed through an update on October 13, and no user information has been compromised. Even before the update, any data from the phone or on the server could not be accessed by the hacker."

Advertisement

It added, "Samsung Electronics takes the security of our products very seriously and remains committed to providing our customers with the best user experience."

Advertisement

The firm did highlight conditions (seen below) required for the "unlikely situation" in which an attacker could remotely lock, unlock, and ring a Samsung device, but once again stressed the attacker would not have been able to access data.

  1. The attacker occupies a way to send a link containing malicious code.
  2. The Find My Mobile user sets up Find My Mobile Remote control 'ON' at his/her device
  3. The user enters up his/her ID and password and logs on Find My Mobile website (http://findmymobile.samsung.com) (If the user doesn't use the website after log-on, it will be automatically logged out)
  4. The user clicks the link in email/instant message/SMS sent by attackers
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi 15C 5G Chipset Details Leaked, Could Launch in India at This Price
  2. Here's When the Nothing Phone 3a Lite Will Launch in India
  3. Vivo X300 and Teleconverter Kit India Prices Tipped Ahead of Launch
  4. Xiaomi 17 and Xiaomi 17 Pro First Impressions
  5. Poco F8 Series Will Be Launched Globally on This Date
  6. Oppo Find X9 Series Price in India Leaked Again Ahead of Debut
  7. OnePlus Ace 6T Launch Timeline Revealed; Will Sport This Snapdragon Chip
  8. Black Ops 7 Faces Backlash Over Alleged GenAI Use for In-Game Artwork
  9. Raktabeej 2 Arrives on OTT Platforms This November: All You Need to Know
  10. Indian Enterprises Increasingly Adopting AI for Internal Workflows: EY
  1. Bison Kaalamaadan OTT Release Date Confirmed: When and Where to Watch This Tamil Sports Action Drama Online?
  2. Samsung Galaxy Z TriFold Testing Commences in the US Ahead of Imminent Launch: Report
  3. Steak ‘n Shake Expands to El Salvador as Bitcoin Strategy Gains Momentum
  4. Samsung Galaxy Buds 4 Pro Leak Hints at Refreshed Design, Head Gestures Feature
  5. Redmi 15C 5G Price in India, Key Specifications Leaked Ahead of Launch: Here’s How Much it Might Cost
  6. India Begins AI Adoption: 47 Percent of Enterprises Use AI for Multiple Use Cases, Says EY
  7. Nothing Phone 3a Lite India Launch Date Confirmed: Expected Specifications, Features
  8. Call of Duty: Black Ops 7 Draws Flak Over Alleged GenAI Use as Steam Player Count Underwhelms
  9. Apple Ordered to Pay Masimo $634 Million in Apple Watch Patent Dispute
  10. OnePlus Ace 6T Launch Timeline Confirmed; Will Debut This Month With Snapdragon 8 Gen 5 SoC
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.