Exynos chipset vulnerabilities

  • 2
    Replies
  • 166
    views
  • Saka's Avatar
    Level 52
    Google's Project Zero team responsible for finding security vulnerabilities found 18 different vulnerabilities affecting a range of Exynos chipsets. As per Samsung website, these are Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Model 5300, Exynos Auto T5123, Exynos W920, Exynos Auto T5124, Exynos Auto T5125, Exynos Auto T5126.

    For some of the issues the time given on the notice (standard 90 days in the industry) has expired (Google has already given an extension, hoping that it would give enough time for updates to patch them). As a result, the the vulnerabilities have been disclosed to the public.

    Here's the blog from Project Zero regarding these vulnerabilities.

    A possibly incomplete list of affected devices:

    • Samsung Galaxy S22, M33, M13, M12, A71, A53, A33, A21s, A13, A12 and A04 series.
    • Vivo S16, S15, S6, X70, X60 and X30 series.
    • The Pixel 6 and Pixel 7 series.
    • Wearables using Exynos W920.
    • Any vehicles that use the Exynos Auto T5123 chipset.
    Google has since released an update to provide a patch for the vulnerability affecting Pixel 6 and 7 phones. So if you have either of these phones, keep it up to date!

    For the rest of the phones, you can minimize the risk by disabling Voice over LTE and Wi-Fi calling in the settings. Keep an eye on the upcoming updates too and install them ASAP.

    Unamused Snarktooth. Advocate for hearing loss & accessibility. Person, friend and a terrible/terrific* artist.
    *delete as appropriate
  • 2 Replies

  • AhmedOsmaan's Avatar
    Level 17
    thanks for the infromation, i have samsung a53
    updating the software now
  • Saka's Avatar
    Level 52
    @AhmedOsmaan Glad the post was useful! The vulnerabilities allow remote code execution, so that's quite severe. But with the patches now, not much to worry about. 😊
    Unamused Snarktooth. Advocate for hearing loss & accessibility. Person, friend and a terrible/terrific* artist.
    *delete as appropriate