Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

81–90 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#81

I'm really struggling to find any concrete information about what this vulnerability actually is. Does anyone know where to look for a good summary?

Search CVE numbers.

https://www.cve.org/CVERecord?id=CVE-2025-48633

Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in.

Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.

Re: Google confirms Android attacks; no fix for most Samsung users

#82
post #5

No fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.

I switched away from my flagship Samsung tablet when they pushed it to quarterly updates, meaning security issues often went unpatched for a while. In the fine print of the "X years of updates" they mention that they switch devices to updates only every 3 months and then every 6 months down the road.

Re: Google confirms Android attacks; no fix for most Samsung users

#83
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

[deleted]

Re: Google confirms Android attacks; no fix for most Samsung users

#84

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

> if I don't install any crap on my phone I am safe? We don't know. Practically no technical information is released about the bug, for what I care any play store app may exploit this at one time or another and there's no way to know. It's not like everyone and their CFO are shy of exploiting any user data they can get their greedy hands on.

CVE records are public. All info is there.

Re: Google confirms Android attacks; no fix for most Samsung users

#85

Earlier quoted context omitted.

How quickly did GrapheneOS roll out the update?

Three days ago. https://grapheneos.org/releases#2025120400 https://github.com/GrapheneOS/platform_manifest/releases/tag... https://grapheneos.social/@GrapheneOS/115666650605430196 not sure how soon it made it to a majority of devices, but i do have it rn EDIT: I was wrong, it's actually first mentioned in https://grapheneos.org/releases#2025102200 oct 22? https://github.com/GrapheneOS/platform_manifest/releases/tag..…

[deleted]

Re: Google confirms Android attacks; no fix for most Samsung users

#86

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

Yes (with caveats)

In todays world, web based exploits are pretty rare. The only time you really see this happen is with full proprietary systems like IPhones because the software stack on those is all intertwined between kernel code and user code, and things like sending a text message with some formatted characters can lead to reboots of phones. But even then, to gain a full command line shell or steal secrets is either impossible due to attack surface, or requires the phone to be in a specific state, like fully factory reset.

The only real danger is chains of trust being compromised, as in some attacker manages to insert malitious code into an already trusted app that uses these exploits.

On a side note i get kick out of reading HN comments about exploitation and hacking. I think people firmly believe that with enough time, a hacker can figure out how to basically take over your phone given any exploit, no matter what it is.

Re: Google confirms Android attacks; no fix for most Samsung users

#87

nice list of vulnerabilities and source changes https://source.android.com/docs/security/bulletin/2025-12-01

CVE-2025-54957 critical rce in Dolby audio processing is a worry.

https://source.android.com/docs/security/bulletin/pixel/2025...

Re: Google confirms Android attacks; no fix for most Samsung users

#88

I'm really struggling to find any concrete information about what this vulnerability actually is. Does anyone know where to look for a good summary?

Search CVE numbers. https://www.cve.org/CVERecord?id=CVE-2025-48633 Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in. Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.

In other words, continue as normal: Don't install random crap you don't trust. That this is even newsworthy is kind of strange.

Re: Google confirms Android attacks; no fix for most Samsung users

#89
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Samsung for the longest time was releasing updates way too late, and what they were releasing monthly was old patches.

Buying a device directly from Samsung may be different, but the manufacturer still has to usually convert the pure android update to their branch.

Still, trying to find a pure android phone is important. More manufacturers used to make them.

Example: https://www.androidauthority.com/best-smartphones-stock-andr...

Re: Google confirms Android attacks; no fix for most Samsung users

#90
post #73

Earlier quoted context omitted.

I vote to just change the spelling to what almost everyone already thinks it is anyways. It'll still be just as weird. But "chs" is just nonsensical . The idea that it would sound like "sh" is baffling. I mean, I know this is English spelling which is not known for its regularity, but this is just too much.

> But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling In the word "french" C H is pronounced sh and nobody bats an eye, I don't think it's that outlandish that someone once read it as fuch-sia, incorrectly splitting it compared to the original. In the language French, fuchsia is unequivocally read something more like few-shia, and I'd bet that even though it comes from German Fuchs-ia (f…

> In the word "french" C H is pronounced sh

No, it's not. Unless you think the "n" in french is pronounced "nt".

Post reply on HN