Google's Project Zero analyst team probes Android device for vulnerabilities
Google has discovered 11 potentially high-impact security issues on Samsung’s Galaxy S6 Edge using a series of tests to assess the device’s vulnerabilities.
After a week of testing, the analysts identified device drivers and media processing as the weakest areas on Samsung’s flagship device. Although hindered by a number of effective security measures, they found three logic issues, deemed trivial, that were also easily found and exploited.
Samsung has already patched eight of the problems in its October Maintenance Release, identified by Google’s Project Zero analyst team, and intends to release the final three fixes as part of a security update within the month.
In a blog post, Project Zero Team Member Natalie Silvanovich said, “OEMs are an important area for Android security research, as they introduce additional (and possibly vulnerable) code into Android devices at all privilege levels, and they decide the frequency of the security updates that they provide for their devices to carriers.”
The Project Zero team sought out vulnerabilities in the Galaxy S6 Edge, selected for its popularity, then reported them to Samsung to see how long it would take the manufacturer to fix the security risks.
Silvanovich continued, “The majority of these issues were fixed on the device we tested via an OTA update within 90 days, though three lower-severity issues remain unfixed. It is promising that the highest severity issues were fixed and updated on-device in a reasonable time frame.”
The majority of Android devices are made by what Google dubs Original Equipment Manufacturers (OEMs), external companies that use an open-source version of the operating software called Android Open-Source Project (AOSP) that is then expanded upon.
OEMs like HTC, LG, and Samsung introduce additional code to their devices and in turn create potential vulnerabilities uncontrolled by Google. They are responsible for fixing identified risks and administering the necessary security updates.
The Project Zero team has included a full report of the identified issues on their blog.
Read more: http://www.itpro.co.uk/security/25549/11-security-problems-found-on-samsungs-galaxy-s6-edge#ixzz3qa
ZEo465