• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Google's Project Zero Discovers 18 Zero-Day Vulnerabilities in Exynos Chipsets

Joined
May 30, 2015
Messages
1,942 (0.56/day)
Location
Seattle, WA
Google's internal team Project Zero, dedicated to the discovery and patching of zero-day vulnerabilities in mobile hardware, software, web browsers and open source libraries disclosed a series of vulnerabilities in Samsung's Exynos chipsets featured across a wide range of mobile devices. Four of these critical vulnerabilities allow for internet-to-baseband remote code execution, and testing conducted by Project Zero confirmed that an attacker can compromise a phone at the baseband level with only the victim's phone number. They believe that with sufficient skill an attacker could exploit these vulnerabilities completely silently and remotely. The fourteen other vulnerabilities are related but considered to not be as critical as they require a more extensive setup including a malicious mobile network operator or local access to the targeted device.

Due to the severity of the main four critical vulnerabilities Project Zero has delayed full disclosure on how the exploit works stating:
Due to a very rare combination of level of access these vulnerabilities provide and the speed with which we believe a reliable operational exploit could be crafted, we have decided to make a policy exception to delay disclosure for the four vulnerabilities that allow for Internet-to-baseband remote code execution.




While patch timelines vary by manufacturer, Google's March 2023 security updates patched the most critical CVE-2023-24033 vulnerability in certain Pixel 6 and Pixel 7 devices, but many devices remain vulnerable to some or all exploits in the report. Devices include:
  • Mobile devices from Samsung, including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 and A04 series
  • Mobile devices from Vivo, including those in the S16, S15, S6, X70, X60 and X30 series
  • The Pixel 6 and Pixel 7 series of devices from Google
  • any wearables that use the Exynos W920 chipset
  • any vehicles that use the Exynos Auto T5123 chipset
Mitigations
Project Zero suggests that users with affected devices who are waiting for security patches can mitigate the risk of the main baseband remote code execution vulnerabilities by disabling Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings. For some devices this is an easy task, however for Google Pixel devices VoLTE is enabled by default with no way to toggle it off. You can however still disable Wi-Fi calling in the Settings app under Network & internet > SIMs > Wi-Fi calling.

View at TechPowerUp Main Site | Source
 
Joined
Aug 22, 2007
Messages
3,593 (0.57/day)
Location
Terra
System Name :)
Processor Intel 13700k
Motherboard Gigabyte z790 UD AC
Cooling Noctua NH-D15
Memory 64GB GSKILL DDR5
Video Card(s) Gigabyte RTX 4090 Gaming OC
Storage 960GB Optane 905P U.2 SSD + 4TB PCIe4 U.2 SSD
Display(s) Alienware AW3423DW 175Hz QD-OLED + AOC Agon Pro AG276QZD2 240Hz QD-OLED
Case Fractal Design Torrent
Audio Device(s) MOTU M4 - JBL 305P MKII w/2x JL Audio 10 Sealed --- X-Fi Titanium HD - Presonus Eris E5 - JBL 4412
Power Supply Silverstone 1000W
Mouse Roccat Kain 122 AIMO
Keyboard KBD67 Lite / Mammoth75
VR HMD Reverb G2 V2
Software Win 11 Pro
Joined
Feb 18, 2023
Messages
245 (0.36/day)
Doesn't matters, next year's samsung cell phones will come with newer Exynos.
 
Joined
May 15, 2020
Messages
697 (0.41/day)
Location
France
System Name Home
Processor Ryzen 3600X
Motherboard MSI Tomahawk 450 MAX
Cooling Noctua NH-U14S
Memory 16GB Crucial Ballistix 3600 MHz DDR4 CAS 16
Video Card(s) MSI RX 5700XT EVOKE OC
Storage Samsung 970 PRO 512 GB
Display(s) ASUS VA326HR + MSI Optix G24C4
Case MSI - MAG Forge 100M
Power Supply Aerocool Lux RGB M 650W
Joined
Oct 18, 2013
Messages
6,263 (1.53/day)
Location
Over here, right where you least expect me to be !
System Name The Little One
Processor i5-11320H @4.4GHZ
Motherboard AZW SEI
Cooling Fan w/heat pipes + side & rear vents
Memory 64GB Crucial DDR4-3200 (2x 32GB)
Video Card(s) Iris XE
Storage WD Black SN850X 4TB m.2, Seagate 2TB SSD + SN850 4TB x2 in an external enclosure
Display(s) 2x Samsung 43" & 2x 32"
Case Practically identical to a mac mini, just purrtier in slate blue, & with 3x usb ports on the front !
Audio Device(s) Yamaha ATS-1060 Bluetooth Soundbar & Subwoofer
Power Supply 65w brick
Mouse Logitech MX Master 2
Keyboard Logitech G613 mechanical wireless
Software Windows 10 pro 64 bit, with all the unnecessary background shitzu turned OFF !
Benchmark Scores PDQ
Next news headline:

"We have discovered another critical exploit in the Exynos Chipsets that will provide direct access to your brain any time/every time you use your phone, thereby granting full read/write permissions to the hackers", hehehe :D
 
Joined
Aug 30, 2006
Messages
7,223 (1.08/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
SSD strategy. Launch, sell, then show reason to buy again!
 
Joined
Feb 18, 2023
Messages
245 (0.36/day)
Most people don’t buy a new phone every year .
Yes, but they will say, our new phones powered by our new Exynos are the most reliable and secure ever, so that means: buy our new cell phones and get rid of your old junk.
 
Joined
Sep 27, 2008
Messages
1,210 (0.20/day)
Those are some pretty big vulnerabilities for a wide variety of devices. :eek:
 
Joined
May 3, 2018
Messages
2,881 (1.19/day)
Exynos is the gift that keeps on giving, and still Google is persisting with Exynos in the Pixel 8.
 
Joined
Mar 18, 2023
Messages
935 (1.45/day)
System Name Never trust a socket with less than 2000 pins
Meanwhile, Pixel 6 users did not get a March 2023 update from Google yet, but a huge warning that we are vulnerable via Wifi calling.
 
Top