
What you need to know
- Google’s Project Zero team has revealed a new vulnerability in the Exynos SoC.
- Phones with these chipsets include the Pixel 6 series, Pixel 7 series, Galaxy S22 models, and more.
- The team points to a baseband remote code execution vulnerability that can be executed based on learning the victim’s phone number.
Smartphones are often ranked by chipset performance, but these SoCs can be vulnerable, and new evidence from Google’s Project Zero team suggests that.
Over the past few months, the Project Zero team has discovered 18 zero-day vulnerabilities in devices including Samsung Exynos modems (via 9to5Google).Of these 18, 4 are seriously ill (1 CVE-2023-24033 IDothers have not yet been assigned a CVE-ID), which could allow an attacker to perform remote code execution from the Internet into the baseband.
In an accompanying blog post, the Project Zero team notes that these four vulnerabilities “allow an attacker to remotely compromise a phone at the baseband level without user interaction, allowing the attacker to gain access to the victim’s phone.” You just need to know the number,” he said.
Security teams claim that while it can be difficult for an unidentified attacker to know a victim’s phone number, it can be done covertly and remotely.
Most Android phone users can check if their chipset is affected from the list provided, (opens in new tab) As advised by Samsung Semiconductor, the project team will provide a list of devices based on our research.
- Including Samsung devices Galaxy S22M33, M13, M12, A71, A53, A33, A21s, A13, A12 and A04 series. (Galaxy S22 owners in the US and some other countries with Qualcomm chips are not affected).
- Some Vivo models have In vivo S16, S15, S6, X70, X60and X30 series.
- Google Pixel 6 and pixel 7 series It comes with Tensor chips developed by Samsung and is based on Exynos.
- An Exynos chipset called Auto T5123 SoC used in cars also appears to be affected.
The new Galaxy S23 uses Qualcomm globally, so it doesn’t suffer like other Galaxy devices.
The CVE-2023-24033 ID vulnerability mentioned above was reportedly fixed on Pixel devices in the recent March 2023 update, but unfortunately it is still not fixed on Pixel 6 and 6a models.
“Turning off these settings removes the risk of these vulnerabilities being exploited.”
project zero team
On the other hand, other non-Pixel devices that have not yet received a fix from the OEM may need to be circumvented to protect themselves from attackers. Our security team advises turning off Wi-Fi calling and Voice-over-LTE (VoLTE) on Samsung Exynos-powered smartphones.