First published: Tue Apr 07 2020(Updated: )
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system image, aka the "SamFAIL" issue. The Samsung ID is SVE-2017-10465 (November 2017).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =7.0 | |
Google Android | =7.1.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Qualcomm MSM8998 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18649 is considered a critical vulnerability as it allows attackers to boot Samsung devices with root privileges.
To mitigate CVE-2017-18649, users should update their Samsung mobile devices to the latest software version provided by Samsung.
CVE-2017-18649 affects various Samsung mobile devices that run Android N (7.x) with Qualcomm MSM8998 chipsets.
An attacker can exploit CVE-2017-18649 to gain unauthorized root access by bypassing the bootloader's integrity check.
CVE-2017-18649 was disclosed in November 2017, along with the related Samsung ID SVE-2017-10465.