- published 1/21/25 5:54 AM •
- updated 13 January 2025 •
- 3 min Read
Critical Vulnerability in Samsung Devices
Alert Rating
Audience
Corporations, Government, Individuals & Families
On this page
Critical Vulnerability in Samsung Devices
Key Details
- CVE ID: CVE-2024-49415
- Severity: Critical rated by Samsung
- Affected Components: Monkey's Audio (APE) decoder, specifically the libsaped.so library
- Impacted Devices: Samsung Galaxy S23, S24, and potentially other models
- Vulnerability Type: Out-of-bounds write
The vulnerability stems from an out-of-bounds write issue in the saped_rec function within the libsaped.so library. This function writes to a DMA buffer allocated by the C2 media service, which has a fixed size of 0x120000 bytes. However, specially crafted APE files with large blocksperframe sizes can cause substantial buffer overflow.
Exploitation Scenario:
The vulnerability is especially concerning because it can be triggered remotely via Rich Communication Services (RCS) messaging, which is enabled by default on Samsung S24 devices. This allows attackers to exploit the vulnerability without any user interaction, increasing the likelihood of successful exploitation.
Affected Versions:
- Samsung S24 (all models and versions)
- Samsung S23 and other Samsung models (potentially affected)
- Refer below website for more details about security updates
- https://security.samsungmobile.com/securityUpdate.smsb
Take Action
Protect yourself
- Apply the December 2024 Samsung security update immediately.
- Ensure that automatic updates are enabled on devices to receive future patches promptly.
GET INVOLVED
Make a Difference
Other Threats
20 January 2025
Critical Vulnerability in F5 Traffix SDC
A critical vulnerability has been discovered in F5 Traffix SDC, linked to Apache Tomcat, which could allow attackers to gain unauthorized access to compromised systems.
Protecting
Corporations, Government
17 January 2025
NVIDIA has released security updates to address multiple vulnerabilities in the NVIDIA Container Toolkit and NVIDIA GPU Operator.
Protecting
Corporations, Government
16 January 2025
Critical Vulnerability in FortiSwitch Devices
A critical vulnerability (CVE-2023-37936) has been discovered in multiple versions of Fortinet FortiSwitch devices. This vulnerability, classified as a use of hard-coded cryptographic key [CWE-321], allows a remote unauthenticated attacker in possession of the key to execute unauthorized code via crafted cryptographic request.
Protecting
Corporations, Government