Samsung is rushing a critical patch to all Galaxy devices amid active exploitation

zohaibahd

Posts: 255   +5
Staff
What just happened? Samsung has confirmed that a crucial security patch for Galaxy devices will start rolling out as early as August, addressing a critical zero-day vulnerability that has been under active exploitation. This comes as a surprise, as previous estimates suggested the fix could take three months or longer.

The urgency stems from the disclosure of a critical vulnerability (CVE-2024-32896) in June that affected Google's Pixel devices, which was serious enough for the US government to order federal employees to update their Pixels by July 4. Initially believed to be a Pixel-exclusive issue, Google later acknowledged that the flaw extended to all Android devices. However, the specifics of this vulnerability were limited.

In addition to CVE-2024-32896, the security-focused Android project GrapheneOS (which was responsible for the initial disclosure) has warned of another vulnerability. They told Forbes that CVE-2024-29745 is actually the "more serious issue" but has yet to be addressed on Android devices beyond the Pixels. However, Google informed the publication that this vulnerability would need to be chained with additional exploits to pose a significant threat.

Due to the fragmented nature of the Android ecosystem and the need for carriers and manufacturers to validate and customize patches for their respective devices, critical updates can take months to roll out.

However, Samsung's swift response is a welcome development. Given the severity of the vulnerabilities and the potential for exploitation, Samsung users are advised to prioritize installing the August update as soon as it becomes available for their specific models.

While the primary focus of the August update is addressing these zero-day vulnerabilities, Samsung is also expected to include other enhancements and features. Rumors suggest the update may bring significant camera improvements to the Galaxy S24 series and introduce new Galaxy AI features.

In the coming months, Samsung is expected to release the first Android 15-based One UI 7.0 Beta update for the Galaxy S24 and other high-end devices. The stable One UI 7.0 update could potentially roll out to most compatible Galaxy phones and tablets before the end of 2024.

Permalink to story:

 
OK, but will that four or five year old device also get the patch? Only time will tell.

However, here I am in Apple iOS land and yeah... I don't have to worry. I know that no matter how old my device is, I will ALWAYS get the security patch. I can't say that about Android and that's scary.
 
OK, but will that four or five year old device also get the patch? Only time will tell.

However, here I am in Apple iOS land and yeah... I don't have to worry. I know that no matter how old my device is, I will ALWAYS get the security patch. I can't say that about Android and that's scary.
And... what's the point of typing this?
 
OK, but will that four or five year old device also get the patch? Only time will tell.

However, here I am in Apple iOS land and yeah... I don't have to worry. I know that no matter how old my device is, I will ALWAYS get the security patch. I can't say that about Android and that's scary.

That is BS. The oldest iPhone supported by iOS 17 is the iPhone XR/XS released in 2018. Older phones are left behind, you cannot even update apps on them after a while.
 
Back