HT TECH wants to start sending you push notifications. Click allow to subscribe

Samsung, LG, Huawei and other Android phones vulnerable to SMS phishing attacks: Researchers

Researchers at the cybersecurity firm said certain Samsung phones are the most vulnerable to this form of phishing attack because they do not have an authenticity check for senders of Open Mobile Alliance Client Provisioning (OMA CP) messages.

By: INDO ASIAN NEWS SERVICE
Updated on: Aug 20 2022, 16:39 IST
Advanced SMS phishing attacks affecting Android phones (Checkpoint)

A security flaw in Samsung, LG, Sony, Huawei and other Android smartphones has been discovered that leaves users vulnerable to advanced SMS phishing attacks, Check Point Research -- the threat intelligence arm of cybersecurity firm Check Point Software Technologies Ltd. said on Thursday.

Researchers at the cybersecurity firm said certain Samsung phones are the most vulnerable to this form of phishing attack because they do not have an authenticity check for senders of Open Mobile Alliance Client Provisioning (OMA CP) messages.

You may be interested in

Mobiles Tablets Laptops
3% OFF
Samsung Galaxy Z Fold5
  • Icy Blue
  • 12 GB RAM
  • 256 GB Storage
₹154,999₹159,999
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
5% OFF
Samsung Galaxy A25 5G
  • Blue Black
  • 8 GB RAM
  • 128/256 GB Storage
₹26,990₹28,499
Buy now
10% OFF
Samsung Galaxy A15 5G
  • Blue Black
  • 6/8 GB RAM
  • 128/256 GB Storage
₹19,390₹21,499
Buy now
Samsung Galaxy Book 3 Pro Intel Evo NP940XFG KC5IN Laptop
  • Graphite Beige
  • 16 GB RAM
  • 1 TB SSD
₹150,990
Check details
30% OFF
LG Gram 17Z90P G AJ65A2 Laptop
  • Black
  • 8 GB RAM
  • 512 GB SSD
₹117,899₹168,000
Buy now
38% OFF
Samsung Galaxy Book 2 360 13 3 Laptop
  • Graphite
  • 16 GB DDR4 RAM
  • 512 GB SSD
₹89,990₹145,990
Buy now
38% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹29,990₹47,990
Buy now
15% OFF
Samsung Galaxy Tab S9 FE Plus 256GB
  • Silver
  • 12 GB RAM
  • 256 GB Storage
₹55,999₹65,999
Buy now
21% OFF
Samsung Galaxy Tab A9 Plus 5G
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹21,999₹27,999
Buy now
Samsung Galaxy Tab A9 Plus 64GB
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹17,180
Check details
Samsung Galaxy Tab A9 LTE
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹14,999
Buy now

"Given the popularity of Android devices, this is a critical vulnerability that must be addressed. Without a stronger form of authentication, it is easy for a malicious agent to launch a phishing attack through over-the-air (OTA) provisioning.

Also read: Looking for a smartphone? To check mobile finder click here.

"When the user receives an OMA CP message, they have no way to discern whether it is from a trusted source. By clicking 'accept', they could very well be letting an attacker into their phone," Slava Makkaveev, Security Researcher, Check Point Software Technologies, said in a statement.

The affected Android phones use OTA provisioning, through which cellular network operators can deploy network-specific settings to a new phone joining their network.

However, researchers at Check Point found that the industry standard for OTA provisioning -- the OMA CP, includes limited authentication methods and remote agents can exploit this to pose as network operators and send deceptive OMA CP messages to users.

The message tricks users into accepting malicious settings that route their Internet traffic through a proxy server owned by the hacker.

The findings were disclosed to the affected vendors in March; Samsung included a fix addressing this phishing flaw in their Security Maintenance Release for May (SVE-2019-14073), LG released their fix in July (LVE-SMP-190006), and Huawei is planning to include UI fixes for OMA CP in the next generation of Mate series or P series smartphones.

However, Sony refused to acknowledge the vulnerability, stating that their devices follow the OMA CP specification.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 05 Sep, 17:56 IST

Sale

Mobiles Tablets Laptops
41% OFF
Samsung Galaxy S23 5G 256GB
  • Green
  • 8 GB RAM
  • 256 GB Storage
₹49,999₹84,999
Buy now
45% OFF
Samsung Galaxy A03s
  • Black
  • 3 GB RAM
  • 32 GB Storage
₹7,449₹13,499
Buy now
15% OFF
Samsung Galaxy A25 5G
  • Blue
  • 8 GB RAM
  • 128 GB Storage
₹24,086₹28,499
Buy now
55% OFF
Samsung Galaxy S21 FE 2023
  • White
  • 8 GB RAM
  • 256 GB Storage
₹33,598₹74,999
Buy now
11% OFF
Samsung Galaxy Tab S8 Ultra
  • Graphite
  • 12 GB RAM
  • 256 GB Storage
₹96,999₹108,699
Buy now
10% OFF
Samsung Galaxy Tab S9 Ultra 512GB
  • Beige
  • 12 GB RAM
  • 512 GB Storage
₹119,999₹133,999
Buy now
30% OFF
Samsung Galaxy Tab S5e LTE
  • Black
  • 4 GB RAM
  • 64 GB Storage
₹34,999₹49,999
Buy now
11% OFF
Samsung Galaxy Tab S9 FE Plus 256GB
  • Silver
  • 12 GB RAM
  • 256 GB Storage
₹50,058₹56,398
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
36% OFF
Infinix INBook X1 Pro Laptop
  • Black
  • 8 GB RAM
  • 256 GB SSD
₹44,990₹69,999
Buy now
29% OFF
Asus VivoBook 15 X515JA EJ522TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹44,689₹62,889
Buy now