Samsung Galaxy S3, Note 2: New Lockscreen Security Exploit Discovered (Video)

Samsung has another lockscreen security exploit on its hands and it was discovered by Terence Eden, who discovered a similar Galaxy Note 2 exploit in February.

Eden notified Samsung and was assured that the company was working on a patch to address the issue. Eden even offered to withhold disclosing the exploit, but Samsung declined. He was able to uncover another lockscreen exploit that he believes affects all Samsung smartphones running TouchWiz.

Eden posted the information below to his blog and also created a YouTube video showing the exploit in action:

"I have discovered another security flaw in Samsung Android phones. It is possible to completely disable the lock screen and get access to any app — even when the phone is 'securely' locked with a pattern, PIN, password, or face detection. Unlike another recently released flaw, this doesn't rely quite so heavily on ultra-precise timing."

Here's how to check if this lockscreen security exploit exists on your Samsung smartphone:

  • From the lock screen, hit the emergency call button.
  • Dial a non-existent emergency services number - e.g. 0.
  • Press the green dial icon.
  • Dismiss the error message.
  • Press the phone's back button.
  • The app's screen will be briefly displayed.
  •  This is just about long enough to interact with the app.
  • Using this, you can run and interact with any app / widget / settings menu.
  • You can also use this to launch the dialer.
  • From there, you can dial any phone number (one digit at a time) and place a phone call.
  • With Google Play, you can search for apps using the voice interface.

PC Magazine reached out to Samsung regarding the issue and received the following statement:

"Samsung considers user privacy and the security of user data its top priority.
We are aware of this issue and will release a fix at the earliest possibility. "

At least Samsung is finally acknowledging the issue, and users should expect a fix in the near future.


© 2024 iTech Post All rights reserved. Do not reproduce without permission.

Company from iTechPost

More from iTechPost