Security Flaw Leaves Samsung Galaxy S III Vulnerable To Remote Wiping

A potential flaw in Samsung’s TouchWiz user interface has left a number of the Korean manufacturer’s smartphones, including the massively popular Samsung Galaxy S III, vulnerable to remote wiping.

The flaw relates to the way the phone reads specially-crafted USSD (Unstructured Supplementary Service Data) code that could cause the phone to perform a factory reset, lock the SIM card so that the device cannot be used or a variety of other malicious acts.

The vulnerability was discovered by Ravi Borgaonkar, who successfully wiped a Samsung Galaxy S III at the Ekoparty security conference.

Samsung Galaxy S III

Exploiting the flaw is as easy as pasting a simple piece of code with the correct dialler instructions onto a website and getting a user to click through to it. The exploit could even be loaded through Near Field Communication (NFC) or a QR code.

The devices affected are the Samsung Galaxy S Advance, Galaxy S II, Galaxy S III, Galaxy Ace and Galaxy Beam.  The Samsung Galaxy Nexus is not affected.

The Next Web was unable to wipe a Samsung Galaxy S running the latest version of Android, 4.1 Jelly Bean, but noted the device wiped by Borgaonkar appeared to be running Ice Cream Sandwich.

This has raised the possibility that it could only affect smartphones running Ice Cream Sandwich, while it has also been suggested that Chrome doesn’t allow the code to be executed, meaning it is only an issue for other browsers.

At the time of publication, Samsung had not responded to TechWeekEurope’s requests for comment.

Are you a security expert? Try our quiz and find out!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

View Comments

  • The reason your galaxy S running JB couldn't be wiped is because it does not have the Touch Wiz interface.. That's where the vulnerability lies...
    . Source-your own article

  • Great article. With all of the recent high-profile security breaches, it is important for everyone to be extra careful with their information. This is definitely an issue that needs to be addressed. At Mosaic Technology, we are huge proponents of being preventative in data security.

    Meaghen
    Mosaic Technology
    http://www.mosaictec.com

Recent Posts

Apple Sales Rise 6 Percent After Early iPhone 16 Demand

Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…

19 hours ago

X’s Community Notes Fails To Stem US Election Misinformation – Report

Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…

20 hours ago

Google Fined More Than World’s GDP By Russia

Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…

21 hours ago

Spotify, Paramount Sign Up To Use Google Cloud ARM Chips

Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…

2 days ago

Meta Warns Of Accelerating AI Infrastructure Costs

Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…

2 days ago

AI Helps Boost Microsoft Cloud Revenues By 33 Percent

Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…

2 days ago