Samsung Galaxy S3 among Android phones vulnerable to remote wipe hack

Samsung Galaxy S3 vulnerable to remove hack
Your S3 could be hacked remotely and you won't know until it's too late

An Android developer/researcher has discovered a major flaw in the way Samsung phones like the Galaxy S2 and Galaxy S3 interact with unstructured supplementary service data (USSD) code.

Ravi Borgaonkar, the researcher who found the issue, said most phones require users to hit the "dial" button before completing the code, but Samsung's unique TouchWiz interface means their devices do not.

This makes Samsung's handsets vulnerable to a string of malicious code that can not only erase a SIM card in its entirety, but can also restore a phone to its factory default settings remotely.

In both instances, the action happens without warning, and will wipe out all pertinent data before a user even knows what has happened.

Samsung not the only maker at risk

Though Borgaonkar has tested this hack out with the Samsung phones, he believes there may be more devices vulnerable to the malware, depending on what version of Android they are operating.

The malware targets specifically Android 2.3, 3.0: Honeycomb, 4.0: Ice Cream Sandwich, and 4.1: Jelly Bean.

As such, HTC, Sony, and Motorola devices could potentially be at risk, including phones like the HTC One X, Motorola Droid Razr M, and Sony Ericsson Experia Active.

According to Borgaonkar, Android Security was made aware of the flaw in June, and has pushed an update out to all carriers to help prevent the hack from taking hold.

The best way for consumers to stay out of trouble is to make sure the latest updates have been installed, and to avoid suspicious links, apps, or QR codes that could be carrying the infecting code.

TechRadar has reached out to Samsung, and will update this story if and when they return request for comment.

Via SlashGear, Ravi Borgaonkar

TOPICS
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Close up of Leica M11-P viewfinder
I wince at the prospect of the rumored Leica M11-V – here's why
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time