By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
Tech News

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices

By Viral Trending Content 2 Min Read
Share
SHARE

Jan 10, 2025Ravie LakshmananCybersecurity / Android

Samsung Devices

Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey’s Audio (APE) decoder on Samsung smartphones that could lead to code execution.

The high-severity vulnerability, tracked as CVE-2024-49415 (CVSS score: 8.1), affects Samsung devices running Android versions 12, 13, and 14.

“Out-of-bounds write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code,” Samsung said in an advisory for the flaw released in December 2024 as part of its monthly security updates. “The patch adds proper input validation.”

Google Project Zero researcher Natalie Silvanovich, who discovered and reported the shortcoming, described it as requiring no user interaction to trigger (i.e., zero-click) and a “fun new attack surface” under specific conditions.

Particularly, this works if Google Messages is configured for rich communication services (RCS), the default configuration on Galaxy S23 and S24 phones, as the transcription service locally decodes incoming audio before a user interacts with the message for transcription purposes.

Cybersecurity

“The function saped_rec in libsaped.so writes to a dmabuf allocated by the C2 media service, which always appears to have size 0x120000,” Silvanovich explained.

“While the maximum blocksperframe value extracted by libsapedextractor is also limited to 0x120000, saped_rec can write up to 3 * blocksperframe bytes out, if the bytes per sample of the input is 24. This means that an APE file with a large blocksperframe size can substantially overflow this buffer.”

In a hypothetical attack scenario, an attacker could send a specially crafted audio message via Google Messages to any target device that has RCS enabled, causing its media codec process (“samsung.software.media.c2”) to crash.

Samsung’s December 2024 patch also addresses another high-severity vulnerability in SmartSwitch (CVE-2024-49413, CVSS score: 7.1) that could allow local attackers to install malicious applications by taking advantage of improper verification of cryptographic signature.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Samsung Galaxy S26 Ultra Release Date Revealed

Dell Technologies Accelerates Enterprise AI with Powerful, Automated Solutions

Chinese astronauts left stranded after space debris smashes return craft

Purple Promo Codes and Deals: Up to 30% Off

Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild

TAGGED: Android, Cyber Security, Cybersecurity, Google, Internet, RCS, Samsung, Technology
Share This Article
Facebook Twitter Copy Link
Previous Article Trump can still vote after sentencing, but can’t own a gun and will have to turn over DNA sample
Next Article US intensifies sanctions on Russian oil: Equities tumble, crude prices rally
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

“Grand Theft Auto 6 Will Make Billions” Say Protesters, Asking “Human Cost” to be Considered
Gaming News
Samsung Galaxy S26 Ultra Release Date Revealed
Tech News
Bitcoin ATMs appear in Nairobi malls as Kenya’s new crypto law faces early compliance test
Crypto
4 Takeaways From the Third CFP Rankings Release of 2025
Sports
Cristiano Ronaldo steals the spotlight at Trump’s White House dinner for saudi prince
World News
Kroger closing automated fulfillment centers as it tries to make delivery faster and cheaper
Business
Dell Technologies Accelerates Enterprise AI with Powerful, Automated Solutions
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

“Grand Theft Auto 6 Will Make Billions” Say Protesters, Asking “Human Cost” to be Considered

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
“Grand Theft Auto 6 Will Make Billions” Say Protesters, Asking “Human Cost” to be Considered
November 19, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?