Hunting bugs in the Samsung Galaxy S6 Edge

Google’s Project Zero, which investigates the security of popular software, recently turned its attention to the Galaxy S6 Edge.

A week of investigation showed that there are a number of weak points in the Samsung Galaxy S6 Edge. Over the course of a week, we found a total of 11 issues with a serious security impact. Several issues were found in device drivers and image processing, and there were also some logic issues in the device that were high impact and easy-to-exploit.

The majority of these issues were fixed on the device we tested via an OTA update within 90 days, though three lower-severity issues remain unfixed. It is promising that the highest severity issues were fixed and updated on-device in a reasonable time frame.

I love that Google has Project Zero, and that the Zero team is not afraid of exposing the weaknesses in the company’s own products (in this case, Android). Few companies out there would allow this.

10 Comments

  1. 2015-11-04 12:44 pm
  2. 2015-11-04 12:45 pm
    • 2015-11-04 1:16 pm
      • 2015-11-04 1:38 pm
      • 2015-11-04 5:17 pm
  3. 2015-11-04 1:17 pm
    • 2015-11-04 6:04 pm
    • 2015-11-05 8:52 pm
  4. 2015-11-05 2:00 am
  5. 2015-11-05 8:34 am