Skip to main content

Samsung patches flaw in update tool to foreclose man-in-the-middle attacks

samsung patches flaw in sw update galaxy tabpro s 9776
Jeffrey Van Camp/Digital Trends
Samsung has patched a flaw in its drive update tool that would have allowed malicious actors to carry out man-in-the-middle (MITM) attacks.

The Samsung SW Update tool tracks the software on your Samsung laptop or computer and alerts you of updates when they are available. Researchers at Core Security discovered that this tool was sending user data back to a server in clear text and unencrypted, making it a prime target for interception.

A second vulnerability revealed that Samsung’s software did not authenticate updates as they were being downloaded from Samsung’s servers. This could in theory allow an attacker to inject their own malware into your computer.

“These vulnerabilities in Samsung SW Update Tool could allow a malicious user to read and modify the requests made both by the user and by the Samsung servers and potentially allow such user to infect the victim with a malware or a remote access tool and gain control over its machine,” said Core security researcher Joaquín Rodríguez Varela in a statement.

“After our report, Samsung implemented a ciphered communication between the tool and its servers and also a verification mechanism of the downloaded drivers.”

According to the advisory, Core Security first notified Samsung of the vulnerabilities it discovered in late January and Samsung released a fix for the update tool in early March following weeks of correspondence with the security researchers.

This isn’t the first time that Samsung has had security issues with the SW Update tool. A Microsoft employee last year found that the SW Update tool in certain Samsung computers was disabling the automatic updates in Windows 8.1. The file that was responsible wasn’t built in from the start on your computer but rather installed unknowingly when SW carried out one of its own updates. Samsung ultimately patched that flaw too, but had denied it was an issue at first.

Editors' Recommendations

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
AMD’s upcoming APUs might destroy your GPU
AMD CEO Lisa Su holding an APU chip.

The spec sheets for AMD's upcoming APU lineups, dubbed Strix Point and Strix Halo, have just been leaked, and it's safe to say that they're looking pretty impressive. Equipped with Zen 5 cores, the new APUs will find their way to laptops that are meant to be on the thinner side, but their performance might rival that of some of the best budget graphics cards -- and that's without having a discrete GPU.

While AMD hasn't unveiled Strix Point (STX) and Strix Halo (STX Halo) specs just yet, they were leaked by HKEPC and then shared by VideoCardz. The sheet goes over the maximum specs for each APU lineup, the first of which, Strix Point, is rumored to launch this year. Strix Halo, said to be significantly more powerful, is currently slated for a 2025 release.

Read more
Hyte made me fall in love with my gaming PC all over again
A PC built with the Hyte Nexus Link ecosystem.

I've never seen anything quite like Hyte's new Nexus Link ecosystem. Corsair has its iCue Link system, and Lian Li has its magnetic Uni system, and all three companies are now offering ways to tie together your PC cooling and lighting devoid of extraneous cables. But Hyte's marriage of hardware, software, and accessories is in a league of its own -- and it transformed my PC build completely.

I've been using some of the foundational components of the ecosystem for about a week, retailoring a build inside of Hyte's own Y40 PC case to see how the system works. It doesn't seem too exciting at first -- Hyte released an all-in-one (AIO) liquid cooler, some fans, and a few RGB strips, who cares? But as I engaged more with the Nexus Link ecosystem, I only became more impressed.
It all starts with the cooler

Read more
How to delete your Spotify account on desktop and mobile
An iPhone with the Stats for Spotify screen on it being held in a hand.

Spotify is home to a bountiful trove of music. With over 615 million users connected to the platform, it’s no wonder it’s one of the biggest music-streaming platforms in town. Still, sometimes we need to put aside a little extra pocket change every month. And one of the first things to go are monthly subscriptions. We know it stinks, but this doesn’t mean your Spotify account needs to disappear forever.

Read more