Samsung Galaxy update patches a number of major security issues

Future
(Image credit: Future)

Samsung has begun rolling out Android's November security updates to the Samsung Galaxy S20 and its other Galaxy smartphones in order to patch a number of serious security vulnerabilities in the operating system.

The update follows the release of the latest Android Security Bulletin for November 2020 which contains details of security vulnerabilities affecting all Android smartphones and not just Samsung devices.

Samsung Galaxy devices are now automatically downloading the new software update which improves the stability of the Camera app, Wi-Fi connectivity and also includes several significant security updates.

Owners of Samsung smartphones are highly encouraged to install the new update as almost all of the vulnerabilities it addresses have either a High or Critical severity rating. If left unpatched, these bugs could be exploited by an attacker to achieve remote code execution, privilege escalation or Denial of Service (DoS) on a vulnerable device.

Android security update

According to the Android security bulletin, the new update patches a number of vulnerabilities in the operating system's framework, media framework and system.

In the framework there are two critical DoS bugs, two high severity privilege escalation bugs, a high severity information disclosure bug and finally a high severity DoS bug. The update also patches one critical and one high remote code execution bug in Android's media framework as well as one high severity escalation of privilege bug and one moderate one. 

When it comes to the Android system itself, the update addresses four high severity information disclosure bugs, one high severity escalation of privilege bug, one high severity DoS bug and a critical remote code execution bug. The Android Security Bulletin explains that the critical security vulnerability in Android's system component is the most severe of all the bugs patched, saying:

“The most severe of these issues is a critical security vulnerability in the System component that could enable a proximal attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.”

While most Samsung Galaxy smartphones will receive the latest security update fixing all of the bugs detailed above, select Galaxy devices such as the Galaxy S10 5G have received a security patch from a few days earlier that does not address all of the vulnerabilities present in the Android operating system.

Via BleepingComputer

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025