Critical zero-day flaws put Samsung phones at risk — is yours vulnerable?

Samsung Galaxy S22 review
(Image credit: Tom's Guide)

Smartphones, wearables and even cars that use Samsung’s Exynos chipsets could be at risk of attack following the discovery of 18 zero-day vulnerabilities by Google’s Project Zero.

The search giant’s bug-hunting team discovered and reported the flaws between the end of last year and the beginning of this year. While some have already been patched, others have yet to receive a fix.

Of the 18 zero-day flaws discovered, four are considered extremely serious as they could allow code to be executed remotely. To make matters worse, these Internet-to-baseband remote code execution (RCE) bugs don’t require user interaction to be exploited.

In a security advisory describing one of the vulnerabilities (tracked as CVE-2023-24033), Samsung provided further details on the flaw, saying: “The baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to a denial of service or code execution in Samsung Baseband Modem.”

It’s worth noting that the best Samsung phones sold in the U.S. aren’t affected as they use Qualcomm’s modems as opposed to those made by Samsung itself. Still, Google’s own Pixel devices and even some of the best Samsung watches that use Exynos chipsets are.

Vulnerable Samsung and Pixel phones

Pixel 7 Pro vs Galaxy S22 Ultra

(Image credit: Future)

In a blog post, head of Project Zero Tim Willis explained that Google’s team conducted tests to confirm that the four most severe zero-day flaws could allow an attacker to remotely compromise a vulnerable Samsung or Pixel device “at the baseband level with no user interaction.” 

Instead of using malware or a malicious app to gain initial access to a victim’s device, an attacker just needs to know their phone number.

The remaining fourteen other zero-day vulnerabilities in Samsung’s Exynos chips aren’t nearly as severe and to exploit them, an attacker would need local access to a vulnerable smartphone or would need to rely on help from a malicious mobile network operator.

Samsung Semiconductor has put together a list of all of the affected Exynos chipsets which can be found in its security advisory above. However, based on Project Zero’s research the following smartphones are affected:

  • Samsung S22
  • Samsung M33
  • Samsung M13
  • Samsung M12
  • Samsung A71
  • Samsung A53
  • Samsung A33
  • Samsung A21s
  • Samsung A13
  • Samsung A12
  • Samsung A04
  • Vivo S16
  • Vivo S15
  • Vivo S6
  • Vivo X70
  • Vivo X60
  • Vivo X30
  • Pixel 6
  • Pixel 6 Pro
  • Pixel 6a
  • Pixel 7
  • Pixel 7 Pro

As we mentioned above though, only Samsung phones sold in Europe and Korea typically use the company’s own Exynos chipsets. Those sold in the U.S. don’t but Samsung’s smartwatches including the Samsung Galaxy Watch 5 and others do. Likewise, any vehicle that uses Samsung’s Exynos Auto T5123 chipset is also affected by these flaws.

Some devices patched and there’s a workaround for others

Google Pixel 7 Pro

(Image credit: Future)

According to BleepingComputer, Samsung has already come up with security updates that address these vulnerabilities and has sent them to vendors that use the affected chipsets in their devices. However, the patches aren’t public yet and can’t be applied by all affected users.

Some device makers have already begun rolling them out though, including Google which fixed the Internet-to-baseband RCE bugs in its March 2023 security updates for Pixel phones.

For those who own an affected device that hasn’t been updated yet, Project Zero does have a workaround. Until you receive the security update patching these zero-day flaws, you should disable both Wi-Fi calling and Voice-over-LTE (VoLTE) as this is the main attack vector that would be used to exploit them.

Once the updates do become available though, you should install them immediately as attackers could be working on ways to leverage these flaws in their attacks now that their existence has been made public.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
Latest in Samsung Phones
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Showing the front of a Galaxy S25 Ultra held in hand
One UI 7 will arrive late for US Samsung users — here’s when it’ll launch for you
samsung galaxy s25 edge mockup at galaxy unpacked
Galaxy S25 Edge is overhyped — I want Samsung to make this phone thinner instead
Samsung Galaxy S23 Ultra
Older Samsung phones are finally getting One UI 7 — here's all the devices
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
Titus Welliver in Bosch Legacy season 3
‘Bosch’ season 3 preview: 5 things to know before the final season on Prime Video
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options