Samsung smartphone users beware. It seems the custom TouchWiz skin found on most Samsung Galaxy smartphones is vulnerable to an attack that can wipe out the phone’s entire contents, including even the SIM data. And this can be done in only one click.

GigaOM reports how only a single line of HTML can do that much damage. In a vulnerability demonstrated by Ravi Borganokar at the Ekoparty security conference, the issue involves tapping a link that executes a data wipe command via the TouchWiz phone dialer.

The report is entitled Dirty use of USSD Codes in Cellular Network, and Borganokar discusses various other means of attacking smartphones and data using USSD commands.

If you’re a Samsung user, you may be familiar with how you can execute all sorts of commands and diagnostics through codes entered in the dialer. The exploit involves directly keying in those commands via a link, and no other user intervention is required other than tapping the link, since TouchWiz automatically dials these codes. Check out the video demonstration below for an example.

Borganokar says this code can even be executed through an NFC wireless transfer or through a QR code, which makes Sammy phone users vulnerable to social engineering attacks that involve tapping or otherwise loading a link.

As an update to the report, Android Police says the vulnerability is not with Samsung phones per se, but with the stock Android browser itself.

The fact is, this is not a Samsung problem, it’s an old Android problem that has been known about for some time. More recent versions of Android avoid the wipe issue, but unpatched devices (like some Samsung phones) may still be vulnerable.

This means the issue can also be replicated on non-Samsung phones, as long as these use unpatched versions of the Android browser.

So far, the issue can be reproduced on these Samsung phones: Galaxy S Advance, Galaxy S2, Galaxy Beam, and Galaxy Ace, among others. Android Police says smartphones that have already been patched, or those that don’t use TouchWiz, are not vulnerable. For instance, the hack does not work on the Galaxy Nexus, since it uses vanilla Android, and without custom skins.

    That's the only issue with Galaxy S3 is that they cracks when dropped & this is easily fixed with a protective case.

          Thanks for the intelligent reply, and I'm sorry if some of the things I mentioned came off as a bit dickish. When I said you promote Apple, I didn't mean in the literal sense, more in the sense that you come to this site to share your positive thoughts and experiences with Apple. Doing so appears out of place though because this is a site that mostly revolves around Android, and with Apple being its main competition, the readers of this site criticise you for being pro-Apple.

            I agree that this site is very biased towards Android, but then again, what would you expect from a site dedicated to Android news?
            I did not mean to offend you by referring to you as an iSheep, because I too think it is a lame and pretty unoriginal term to use and it groups all people who like Apple into one category. I only meant to use it as a way to distinguish the fact that you are a fan of Apple, not in the sense that you are an Apple extremist that follows Apple like some sort of cult. I know that probably wasn’t the best term to use but I was drawing a mind blank due to an overload of school work. I’m sorry for any offence or disrespect this may have brought.
            I think that we may agree on most points when it comes to things like this, but we each have our own personal preference when it comes to smart phones. But hey, the world would be boring if everyone was the same, plus the competition stimulates more innovation from both companies

        Apple Will NOT Replace any iPhone if it's not to customer's standards… When I bought the 4, It was scratched out of the box, I was not able to have it replaced, even after complaining at the corporate level even though the front glass had a 2 inch scratch in the middle… Making the device worthless…

      • jangeloracoma

        We try to let everyone air their own opinions. Unfortunately, that can also include dissenting opinions. Please vote-down any comments or commenters you think are not posting constructive comments. We do try to be proactive in blocking outright spam. But as for trolling, well, that can be subjective.

        Thanks for bringing this to our attention, though.

    Apparently, Android Authority left something important out, which has made an uproar in the community because of their lack of responsibility to their readers:

    “The USSD code issue in the SGS3 is patched, and has been for some time” TeamAndIRCclaims. “Current i747 [AT&T Galaxy S III] and i9300 [European Galaxy S III] firmware are not vulnerable.” An update pushed out to the AT&T Galaxy S III last week apparently patched the loophole, with the i9300 being updated beforehand.”

    excerpt from:

  • poobum

