And you thought the Exynos Modem was your friend
Buckle down, this is a rough ride. Google’s Project Zero team has reported 18 zero-day vulnerabilities affecting his Exynos modems that have been discovered on many of his Android phones over the past few months. All vulnerabilities have been designated as CVEs, but all details about 4 of the 18 vulnerabilities are withheld until solutions to them are widely disseminated. These four allow an attacker to remotely compromise a phone at baseband he level without user interaction and the only information an attacker needs is a phone number.
The Baseband Remote Code Execution Vulnerability is a thorny issue due to the lack of security in the baseband software running the modem to prevent denial of service and code execution. The software is updateable and has resolved similar attacks in the past. This all happens far below the user level, so it can all happen without any instructions being given to the user, without any questionable text or app even appearing.
Unfortunately, this requires the manufacturer (Samsung in this case) to create a fix and hand it off to the provider to push to the user. While many of us can get Android updates directly, some carriers only offer over-the-air updates, and many rely on them. Assuming they actually approved and applied the update.
The list of affected devices is long, Samsung’s S22, M33, M13, M12, A71, A53, A33, A21s, A13, A12, and A0 are all in the Vivo S16, S15, S6, X70, X60, and X30 series. is as vulnerable as your phone. It also applies to all vehicles in which he uses Exynos modems in the entertainment system. It’s unclear which vehicles those are, but we can speculate that the update will be even slower.
Google fixed the vulnerabilities in the Pixel 6 and Pixel 7 series, but don’t celebrate your choice until you’ve read the first above-the-fold story.