Samsung TouchWiz vulnerability will wipe some phones after just clicking a


Recommended Posts

Samsung TouchWiz vulnerability will wipe some phones after just clicking a link

Samsung is finding itself in a spot of bother this morning, as a particular piece of HTML code has emerged that, when clicked, instantly resets the Galaxy S II ? and potentially other Android devices running the TouchWiz UI. Posted by Pau Oliva earlier today, the code was initially thought to affect the current flagship Galaxy S III model, however multiple negative reports and our own testing have shown that it only brings up the phone's dialer, failing to execute the full reset without user intervention. The latter is really the issue here: Samsung's software changes atop stock Android are allowing the GS II to automatically dial the hard reset code, taking away a critical aspect of user control.

The Galaxy S II is the only device we're certain is affected by the problem so far, though Tweakers.net reports successfully recreating it on the Galaxy S Advance as well. We're in touch with Samsung to get a better idea of the full scale and depth of this vulnerability.

Update: we have now managed to test this on an AT&T Samsung Galaxy S III and have confirmed it works on the device. Samsung tells us it's "looking into" the reports.

Source: The Verge

did apple pay those people?

Heaven forbid there is an actual vulnerability in a Samsung product. No, let's blame the evil empire Apple.

Fail comment is fail, remixedcat.

The front page beat you to it, Meph. :p

Meh, I'm not overly concerned. So we just need to avoid TouchWiz, right?

... whoops, I swear I checked the front page and didn't see it. Mea culpa.

Samsung Galaxy S III, designed for humans exploits.

Like there isnt exploits on all other systems as well. There will be a patched released for TW as soon as Samsung readys a patch for it. They were quick to release other patches/changes in TW before...so lets hope they are quick here as well.

The front page beat you to it, Meph. :p

Meh, I'm not overly concerned. So we just need to avoid TouchWiz, right?

Wish Samsung would wake up and just ditch TW.

It's not just Samsung phones (with Touchwiz)...

Update: This issue is, unsurprisingly, a lot more nuanced than the video here lets on. The bug is based in the stock Android browser, is in fact quite old, and has been patched in more recent builds of Android - this is probably why Nexus devices running the most recent OTAs are unaffected. The fact is, this is not a Samsung problem, it's an old Android problem that has been known about for some time. More recent versions of Android avoid the wipe issue, but unpatched devices (like some Samsung phones) may still be vulnerable.

http://www.androidpolice.com/2012/09/25/new-exploit-could-force-factory-reset-on-many-samsung-phones-running-touchwiz/

Did I say otherwise? No.

But yet you only mentioned Samsung.

We all know you dont like android and if all you are going to do is make comments like "Samsung Galaxy S III, designed for humans exploits." here and then again on TFP, then keep it to yourself.

But yet you only mentioned Samsung.

That's because this thread involves Samsung only. Let me hold up a mirror for a second or two: Did you mention how most, if not all, major companies tend to spin things around if it suits their needs and thus can use it to their advantage? No, you did not. You purely talked about how Apple does it. I suggest you at least try to drop the display of double standards before calling others out. If not take a page from your own book and simply keep the remarks to yourself.

We all know you dont like android and if all you are going to do is make comments like "Samsung Galaxy S III, designed for humans exploits." here and then again on TFP, then keep it to yourself.

I have very little against Android in its vanilla state. In fact I recently bought my mom a Nexus 7 as a birthday present to take with her on holiday. Very nice device, especially for its price. Too bad huh?

This topic is now closed to further replies.
  • Posts

    • Are they marketed as an entry into astronomy or astrophotography? I do astrophotography. With big rigs, lots of computers, cables and headaches. I love it. And by learning this ridiculously complex hobby, I’ve learned about the objects I’m shooting. Astronomy followed from photography.
    • Microsoft confirms Recycle Bin bug across all versions of Windows by Usama Jawad A couple of days ago, we reported that the latest Patch Tuesday update has seemingly resulted in a lot of issues for many users, including OneDrive and Dropbox access problems, BitLocker recovery lockouts, and BSODs. Although Microsoft is yet to acknowledge these bugs, it has confirmed another, relatively smaller issue across all supported versions of Windows. In an update on its Windows Release Health Dashboard, Microsoft has confirmed that after installing June's Patch Tuesday update (KB5094126), you'll experience unexpected behavior when leveraging Recycle Bin. Basically, when you attempt to delete an item from the Recycle Bin, the confirm dialog will show you the internal file name of that content rather than the actual name. For example, the file may be named abc.png, but the confirm dialog will ask if you're sure that you want to permanently delete $Rxxxxx.png from the Recycle Bin. This is pretty much it for the scope of the bug itself; it just displays the wrong name in the confirm dialog. The correct name will be shown in the list view of the Recycle Bin and if you restore the file, it will return with the correct name as well. This issue affects pretty much all supported versions of Windows client and server, including: Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10 Enterprise LTSC 2021; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSB 2016 Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012 As things currently stand, Microsoft is working on a concrete solution that will be released in a "future" Windows update. It remains to be seen if the firm will wait till the next Patch Tuesday or roll out an out-of-band (OOB) fix. The good news is that commercial customers can deploy a workaround right now, but they will have to reach out to Microsoft Support for Business for additional details.
    • They said by this time everyone will have flying cars. WELL...
    • A study by physicist Henry Tye of Cornell University suggests that the universe may not expand forever. Instead, it could eventually stop expanding, begin contracting and end in a "Big Crunch" roughly 20 billion years from now. Maybe not as we now know that time can flow backwards.
    • Of course. Simply reverse the polarity.
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      577
    2. 2
      +Edouard
      183
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      72
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!