Samsung has disclosed multiple security vulnerabilities affecting Galaxy series devices in 2024, including two significant zero-day flaws that required immediate patching. The latest security update continues Samsung’s ongoing efforts to strengthen the security infrastructure of its Galaxy ecosystem, which has previously included enhanced biometric authentication systems and regular security maintenance releases.
Google’s Threat Analysis Group (TAG) identified a zero-day vulnerability tracked as CVE-2024-44068, which involves a use-after-free issue enabling privilege escalation on affected Android devices. The vulnerability, discovered by researchers Xingyu Jin from Google Devices & Services Security Research and Clement Lecigene from Google TAG, affects multiple Exynos processors including the 9820, 9825, 980, 990, 850, and W920 models. These processors have been fundamental to Samsung’s mobile strategy since the company began developing its own Exynos chipsets for enhanced performance and security features. Samsung addressed this vulnerability through security updates released in October 2024.
A second significant vulnerability, CVE-2024-49415, was identified by Google Project Zero researcher Natalie Silvanovich. The zero-click vulnerability manifests as an out-of-bound write issue in libsaped.so, affecting Samsung Galaxy S23 and S24 devices. The flaw is specifically connected to Google Messages’ transcription service when rich communication services (RCS) are enabled. The discovery comes at a crucial time as RCS messaging gains prominence, with major platforms implementing end-to-end encryption for enhanced security. The vulnerability involves the Monkey’s Audio decoder on the Samsung S24, where the saped_rec function in libsaped.so can write beyond allocated buffer limits, potentially leading to buffer overflow conditions.
The technical specifics of the vulnerability involve a dmabuf allocated by the C2 media service with a size of 0x120000, where saped_rec can write up to three times the blocks per frame when the input’s bytes per sample is 24. The issue is particularly concerning given Samsung’s recent focus on enhanced security features in their One UI platform. Samsung addressed this vulnerability in their December 2024 SMR Release 1, maintaining their track record of prompt security patch deployments for critical vulnerabilities.
Sources: Sammyfans, Security Affairs, Sammyfans, Security Affairs