Friday, June 28, 2013

Samsung GALAXY S4 - security vulnerability

Serious security vulnerability was recently discovered on the Samsug flagship Galaxy S4 device , claimimg that attackers can use it to silently send text messages



Qihoo 360 Technology , an antivirus company based in chaina, saiid that  this specific particular vulnerability is related to the "cloud backup" feature of Galaxy S4 , which was no properly protected and can be abused

This vulnerability was first discovered on june 17 2013  and already reported the issue to Samsung  abd the company is already in the process of develpping an official update to fix this vulnerability

A rouge mobile application could contain code exploting the vulnerability to send fraudulent scam text messages ordering premium-rate services , the firm said

By exploting the vulnerables cloud backup feature , malware could pretend to be the identity of any contact , friend relative,or an organization when faking phishing messages .when these phishing messages/SMS  are received  users  may be tricked into clicking fraudlent links or disclosure sensitive personel inforamtion.

Qihoo recomends Galaxy s4 users temporarily disable the cloud backup feature when not in use.A temporary fix has also been made by Qihoo 360  and can be deactivated oonce the security flaw has been patched.