Samsung Touchwiz security vulnerability

*“If you have a Samsung mobile phone running Android with the TouchWiz UI, there’s a newly discovered vulnerability that could result in an accidental factory data reset by simply accessing a link from your phone. This includes some Galaxy S II and Galaxy S III devices. UPDATE: Other Android devices not using TouchWiz are also affected.”
*

This story is still unfolding with Samsung promising updates in the near future:
"It has been confirmed that you shouldn’t be affected by this as long as you’re using the latest S3 rom

in short update your firmware

Samsung TouchWiz Devices Vulnerable to Mischief - F-Secure Weblog : News from the Lab

Re: Samsung Touchwiz security vulnerability

Umm for us noobs can you tell me what I have to do. How shall I update the firmware?

Re: Samsung Touchwiz security vulnerability

Click on Menu > Settings > System Update > Update firmware

Also do Update Samsung Software, Profile and PRL

Re: Samsung Touchwiz security vulnerability

I don't see system update under settings. I did find samsung software but there were no updates.

Re: Samsung Touchwiz security vulnerability

You can so software update by clicking on about device, which is at the end of the settings menu.

I also don’t see the System Update.

But I believe you can also make firmware updates via the Samsung Kies app on ur laptop, via a USB cable plugging the phone in. NOt sure if that’s what is needed for the above.

PS: Tofi, I got that news on my Google Alert today :blush:.

Re: Samsung Touchwiz security vulnerability

To check if you phone is vulnerable to this attack go tyo this site (this test is benign and wouldn’t cause any harm to your phone):
How to tell if your Samsung phone is vulnerable to today’s USSD hack | Android Central

When you run the test (on the phone) if the dialer comes up and shows your IMEI number then your phone is susceptible to this attack. If it doesn’t show that number then your phone is fine.

If your phone is vulnerable you can download and install an alternate dialer app, “Dialer One” (see below) to get around this issue till the new updates are available in your area:
https://play.google.com/store/apps/details?id=kz.mek.DialerOne&feature=search_result#?t=W251bGwsMSwxLDEsImt6Lm1lay5EaWFsZXJPbmUiXQ..

Re: Samsung Touchwiz security vulnerability

Yay, the IMEI number didn't show up on my phone. I did just do the software update this morning. It automatically gave me the notification that an update is available. When I checked for it yesterday it said there was no update needed.

Re: Samsung Touchwiz security vulnerability

Dialer appeared/no code. Pretty darn cool!