This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here

 

UPDATED: Samsung Galaxy S3 ‘can be wiped’ using hidden web code

By Sooraj Shah

26 Sep 2012

View Comments
Samsung Galaxy S3 LTE Android Jelly Bean

Attendees at a security conference were left stunned when a researcher demonstrated how a hidden web code could allow a Samsung Galaxy S3's data to be completely wiped.

The code, which is currently available online and consists of 11 digits, was unveiled at an event in Argentina, the Telegraph reported.

Further reading

South Korean firm Samsung has since issued a software fix, which it says will eradicate the problem.

In a statement it said: "We would like to assure our customers that the recent security issue concerning the Galaxy S3 has already been resolved through a software update.

"We recommend all Galaxy S3 customers to download the latest software update, which can be done quickly and easily via the Over-The-Air (OTA) service".

Vulnerability

Security researcher Ravi Borgaonkar, based at the Technische Universitat Berlin, had shown conference attendees how the code can be embedded in the HTML code of a web page. If a Samsung Galaxy S3 owner visits such a page, the smartphone will automatically restore itself to factory settings – deleting all data without allowing the user to cancel the operation.

All Samsung devices that use the Android operating system including the Galaxy S2 were affected, but other Android devices such as those on HTC were not, according to Borgaonkar.

In his presentation, Borgaonkar showed how the code could be imbedded into a text message or be put into the web browser using a QR code or NFC tag.

He warned that there were other codes built into Samsung devices that left them vulnerable – one, apparently, can be used to shut down a SIM card – but did not want to disclose further details for fear of criminal activity.

Before the software update was released Borgaonkar advised those with Samsung devices that run on Android to switch off "service loading" in settings and disable QR code and NFC apps.

Reader comments

blog comments powered by Disqus

Newsletters

Does Google know too much about you?

Google's linked data policy, which came into effect on March 1, allows the company to collect information about its users across all its products, services and websites and store it in one place. This has been criticised by organisations ranging from CNIL to Microsoft, all of whom have expressed concerns that it's difficult to tell which data Google collects and how it's used. Now the Information Commissioner's Office is investigating whether Google's privacy policy is compliant with UK law. Are you worried that Google knows too much about you?

43 %

5 %

13 %

39 %