Samsung and LG phones at risk from Qualcomm security flaw

(Image credit: Shutterstock.com)

Some of the world's most popular smartphones could be at risk of cyberattack after researchers uncovered new vulnerabilities in Qualcomm chipsets.

Experts from Check Point discovered a set of vulnerabilities affecting Qualcomm hardware which could potentially allow an attacker to steal critical information from Samsung, LG and Motorola smartphones.

The cybersecurity firm's findings show that the 'secure world' found in Qualcomm's CPUs suffer from a flaw that could lead to protected data being leaked, devices rooting, bootloader unlocking and the execution of undetectable APTs.

The news of these new flaws comes only months after Qualcomm patched a vulnerability that would allow an attacker to extract private data and encryption keys stored in the chipset's secure world.

Check Point first unrelieved its findings at the Recon Montreal security conference back in June and the chipmaker has since issued fixes for all of the flaws after they were disclosed. Samsung and LG have both issued patches to fix their devices while Motorola is still working on a patch.

Qualcomm Trusted Execution Environment

Qualcomm's chips contain a secure area inside the processor known as a Trusted Execution Environment (TEE) which is used to ensure that the code and data they contain remains confidential and secure. The Qualcomm Trusted Execution Environment (QTEE) is based on TrustZone technology from Arm and it allows for sensitive data to be stored in such a way that it can't be tampered with.

The chipmaker's secure world also provides additional services through trusted third-party components, known as trustlets, which are loaded and executed in the TEE by the trusted OS within TrustZone. These trustlets serve as a bridge between the “normal world” where the device's main operating system resides and the TEE which allows data to move between the two worlds.

However, Check Point conducted a four month long investigation using an automated testing method called fuzzing in which its researchers managed to execute a trustlet in the normal world and loaded a modified variant they needed to communicate with in the secret world. The firm used fuzzing to target Samsung, Motorola and LG's trustlet implementation and during the process it uncovered multiple security flaws.

These flaws could allow an attacker to execute trusted apps in the normal world, load a patched trusted app into the secret world and even load trustlets from another device.

While TEEs are certainly a new attack frontier that cybercriminals will likely look to exploit, at this time there is no evidence that the vulnerabilities discovered in Qualcomm's chips have been exploited in the wild.

Via Bleeping Computer

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Phone & Communications
ThinkPhone 25 by Motorola
I reviewed the ThinkPhone 25 by Motorola and while it's not as fast as its predecessor, it's the superior phone in so many ways
FRITZ!Box 7690 WiFi 7 Router
FRITZ!Box tries to embrace both business and home customers with its new 7690 router
Ulefone Armor Pad 4 Ultra Thermal
Other than screen reflection, I’m still looking for the downside to the Ulefone Armor Pad 4 Ultra Thermal tablet
Unihertz Tank Pad 8849
Carrying the Unihertz Tank Pad 8849 provided me with a full workout
Doogee Fire 6
The Doogee Fire 6 is another rugged retro SoC phone that fails to justify its cost or your interest
AGM H Max
AGM H Max rugged phone review
Latest in News
Homepage of Manus, a new Chinese artificial intelligence agent capable of handling complex, real-world tasks, is seen on the screen of an iPhone.
Manus AI may be the new DeepSeek, but initial users report problems
Google Maps
Nightmare Google Maps glitch is deleting timelines, and there isn't a fix yet
Twitter social media application change logo to X. Elon Musk CEO of twitter rebranded Twitter to 'X'. Social media application technology concept.
X is down again – Elon Musk confirms 'massive cyberattack' as former Twitter site hit by fourth outage today
Joe Goldberg and Kate Lockwood sitting at a table and looking at the camera in You season 5.
Netflix releases a killer new trailer for You season 5 but my favorite character is missing from Joe's final chapter
Person using Dyson V8 vacuum
Dyson vacuums have one big problem and I don't understand why
A laptop on a desk with the Windows 11 background on its screen.
Microsoft is adding image editing and compression to its Windows Share feature - and I couldn't be happier