5 Generations of Samsung Galaxy Phones Carried Security Risk

Samsung Galaxy Security Risk Featured

There really isn’t much about hacking, malware, and security in the tech world that’s surprising anymore. Except for this. A security risk has been found in Samsung Galaxy smartphones – five generations of the handsets. It’s a design flaw that wasn’t caught until now. Even more surprising? It appears hackers never found this security risk.

Also read: Samsung Galaxy Owners to Get Digital Car Key Ability

Researchers Find Samsung Galaxy Design Flaw

Tel-Aviv University researchers in Israel – Alon Shakevsky, Eyal Ronen, and Avishai Wool – wrote a paper titled “Trust Dies in Darkness: Shedding Light on Samsung’s TrustZone Keymaster Design,” detailing their findings about the security risk in Samsung Galaxy phones.

The researchers explain in the paper how they were able to remotely extract cryptographic keys. They were also able to get past the FIDO2 authentication to reach highly sensitive data on all the recent Samsung Galaxy models.

Samsung Galaxy Security Risk S21

The phones carry the Trusted Execution Environment (TEE), which includes the TrustZone Operating System (TZOS). While it may sound like a system that would keep your passwords and sensitive data safe, the paper’s authors were able to break through.

Once they broke through the structure, they created an exploit that allowed them to get to data that was protected by the hardware of the Samsung Galaxys. As if that weren’t enough, the researchers created a second exploit that allowed them to affect more recent Samsung phones running Android 9 and later that you would think would be protected from such risks.

The Samsung Galaxy phones had cryptographic keys that protected data with AES-GCM encryption. This meant apps could only reach that data if they went through the Samsung Keystore.

Samsung Galaxy Security Risk S20

The Tel-Aviv researchers explained that “the implementation of the cryptographic functions within the TZOS is left to the device vendors who create proprietary undocumented designs.” Yet, Samsung had a very flawed design that allowed the researchers to break through with two exploits.

What this Means for Galaxy Owners

Through a process that seems like extreme luck, if you’re a Samsung Galaxy owner and have done your due diligence with security updates, you’re probably safe.

Despite the design flaw that allowed two huge security risks, there are no known exploits – other than the ones created by the researchers – that have taken advantage of the two vulnerabilities they found: CVE-2021-25444 and CVE-2021-25490.

Hackers could have used malware to get root or kernel privileges, but none ever did. Again, this design flaw goes back through five generations: Samsung Galaxy S8, S9, S10, S20, and S21.

Samsung Galaxy Security Risk Back

Truthfully, though, Samsung Galaxys have been protected for the past year. Last August, CVE-2021-2544 was patched by Samsung, who had learned of the security risk from the Tel-Aviv researchers. Two months later, CVE-2021-25490 was patched as well. If you’ve kept your phone updated, you’re probably safe.

If you’re not sure if you have the most recent updates, check the update information in “Settings -> About Phone -> Software Information.”

You’d be wise to update now if you haven’t, as hackers have undoubtedly read this news as well. They know there are approximately 100 million Samsung Galaxy phones with this security flaw.

If you’re looking for a good reason to have an older Samsung Galaxy phone, the S9 is currently the only phone known to help you test for COVID.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.
When survivors near Lake Nyos woke on the morning of 22 August 1986, the cattle were dead in the fields, the birds had fallen out of the trees, and 1,746 of their neighbours were lying where they had stood the night before, with no fire, no flood, and no wound to explain it.
In October 2002, a Russian scientist named Dimitri Malashenkov stood up at a space conference in Houston and quietly explained that the dog Laika, whom the Soviet Union had publicly mourned as a heroic week-long orbiter in 1957, had actually died of heat and panic within about five hours of launch.