Wednesday , June 25 2025
Samsung

Samsung mobile devices 25 flaws patched

Samsung has patched 25 vulnerabilities in its mobile devices. This is to strengthen them against code execution and privilege escalation attacks. Samsung is continuously working to improve the security of its smartphones and tablets, protecting the safety and privacy of its users.

Samsung recently disclosed vulnerabilities, known as Samsung Vulnerabilities and Exposures (SVE) items, in their latest security bulletin.

WhatsApp banned on all US House of Representatives devices

The U.S. House of Representatives has banned congressional staff from using WhatsApp on government devices due to security concerns, as...
Read More
WhatsApp banned on all US House of Representatives devices

Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

Kaspersky found a new mobile malware dubbed SparkKitty in Google Play and Apple App Store apps, targeting Android and iOS....
Read More
Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

OWASP has released its AI Testing Guide, a framework to help organizations find and fix vulnerabilities specific to AI systems....
Read More
OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

In a major milestone for the country’s digital infrastructure, Axentec PLC has officially launched Axentec Cloud, Bangladesh’s first Tier-4 cloud...
Read More
Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

Hackers Bypass Gmail MFA With App-Specific Password Reuse

A hacking group reportedly linked to Russian government has been discovered using a new phishing method that bypasses two-factor authentication...
Read More
Hackers Bypass Gmail MFA With App-Specific Password Reuse

Russia detects first SuperCard malware attacks via NFC

Russian cybersecurity experts discovered the first local data theft attacks using a modified version of legitimate near field communication (NFC)...
Read More
Russia detects first SuperCard malware attacks via NFC

Income Property Investments exposes 170,000+ Individuals record

Cybersecurity researcher Jeremiah Fowler discovered an unsecured database with 170,360 records belonging to a real estate company. It contained personal...
Read More
Income Property Investments exposes 170,000+ Individuals record

ALERT (CVE: 2023-28771)
Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

GreyNoise found attempts to exploit CVE-2023-28771, a vulnerability in Zyxel's IKE affecting UDP port 500. The attack centers around CVE-2023-28771,...
Read More
ALERT (CVE: 2023-28771)  Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

CISA Flags Active Exploits in Apple iOS and TP-Link Routers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included two high-risk vulnerabilities in its Known Exploited Vulnerabilities (KEV)...
Read More
CISA Flags Active Exploits in Apple iOS and TP-Link Routers

10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

SafetyDetectives’ Cybersecurity Team discovered a public post on a clear web forum in which a threat actor claimed to have...
Read More
10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

The problems affected different parts of Samsung devices, such as the operating system, firmware, and Samsung’s own software.

The vulnerabilities could let bad actors run harmful code on the devices or increase their privileges, getting unauthorized access to important information or system functions.

Samsung quickly responded to security threats, showing their commitment to protecting users from cyber threats.

SVE-2023-1778 (CVE-2024-20866):
There was a vulnerability in the Setupwizard that allowed unauthorized users to bypass device setup authentication. The patch for this vulnerability fixed the issue by removing unnecessary internet access during setup to prevent unauthorized access.

SVE-2023-2193 (CVE-2024-20855):
There was a problem with access control in the multitasking framework, which could have let unauthorized users access and control multitasking functions, allowing privilege escalation attacks. The update fixed this by imposing stricter access controls.

SVE-2023-2265 (CVE-2024-20856):
Samsung’s Secure Folder had a security flaw that allowed hackers to bypass authentication and access private data stored in it. The flaw has been fixed.

SVE-2024-0092 (CVE-2024-20861) and SVE-2024-0096 (CVE-2024-20862):

SveService had vulnerabilities: a use-after-free issue and an out-of-bounds write flaw. Both could allow arbitrary code execution. The patches fixed these memory corruption issues to prevent exploitation.

SVE-2024-0234 (CVE-2024-20865):
An authentication bypass in the bootloader allowed physical attackers to flash any images. The patch has added verification checks to prevent unauthorized flashing, improving the security of the device’s boot process.

SVE-2024-0357 (CVE-2024-20864):
A security issue in DarManagerService was fixed. This issue could have allowed unauthorized access, which could lead to further attacks.

The fixed vulnerabilities were included in a larger security update from Google that addressed issues with the Android operating system.

Check Also

Apex One

Alert
Trend Micro Apex One Flaw Allow Attackers to Inject Malicious Code

Serious security vulnerabilities in Trend Micro Apex One could allow attackers to inject malicious code …

Leave a Reply

Your email address will not be published. Required fields are marked *