{"id":25412,"date":"2025-09-16T18:06:06","date_gmt":"2025-09-16T18:06:06","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/25412\/"},"modified":"2025-09-16T18:06:06","modified_gmt":"2025-09-16T18:06:06","slug":"samsung-patches-zero-day-security-flaw-used-to-hack-into-its-customers-phones","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/25412\/","title":{"rendered":"Samsung patches zero-day security flaw used to hack into its customers&#8217; phones"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Samsung says it has fixed a <a href=\"https:\/\/techcrunch.com\/2024\/12\/23\/techcrunch-reference-guide-to-security-terminology\/#zero-day\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">zero-day security vulnerability<\/a> that is being used to hack into its customers\u2019 phones.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The phone maker said <a rel=\"nofollow noopener\" href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\" target=\"_blank\">the security flaw<\/a>, discovered in a software library for displaying images on Samsung devices, allows hackers to remotely plant malicious code on Samsung devices running Android 13 through the most recent version, Android 16.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Samsung\u2019s advisory said security teams from Meta and WhatsApp privately notified the company on August 13 and was told that \u201can exploit for this issue has existed in the wild.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Samsung did not provide a list of devices affected by the vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">The bug is known as a zero-day because the vendor, in this case Samsung, was given no time to fix the bug before it was exploited.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not immediately clear who is behind the hacking campaign or how many Samsung customers are affected, and a spokesperson for Samsung did not respond to a request for comment sent prior to publication. <\/p>\n<p class=\"wp-block-paragraph\">But the security fixes coincide with a flurry of security updates from other phone software vendors aimed at countering an ongoing spyware campaign.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Samsung\u2019s security patches follow <a href=\"https:\/\/techcrunch.com\/2025\/08\/29\/whatsapp-fixes-zero-click-bug-used-to-hack-apple-users-with-spyware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">separate security fixes issued by Apple and WhatsApp<\/a> in August, fixing vulnerabilities that security researchers say were used to target both iPhone owners and Android users.<\/p>\n<p class=\"wp-block-paragraph\">WhatsApp told TechCrunch at the time that the messaging app maker sent fewer than 200 notifications to affected users whose phones were targeted or compromised by the campaign.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">For its part, Apple has not commented on the vulnerabilities it patched, except <a rel=\"nofollow noopener\" href=\"https:\/\/support.apple.com\/en-us\/124925\" target=\"_blank\">to say<\/a> that the flaw was used in an \u201cextremely sophisticated attack against specific targeted individuals.\u201d <\/p>\n<p class=\"wp-block-paragraph\">Apple periodically notifies new victims of potential spyware attacks, and asks them to seek help from <a href=\"https:\/\/techcrunch.com\/2024\/12\/20\/why-apple-sends-spyware-victims-to-this-nonprofit-security-lab\/\" rel=\"nofollow noopener\" target=\"_blank\">Access Now\u2019s digital security lab<\/a>. The tech giant most recently on September 3 notified an unspecified number of its customers that their phones were targeted as part of a spyware campaign, <a href=\"https:\/\/techcrunch.com\/2025\/09\/11\/france-says-apple-notified-victims-of-new-spyware-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">according to the French government<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Samsung says it has fixed a zero-day security vulnerability that is being used to hack into its customers\u2019&hellip;\n","protected":false},"author":2,"featured_media":25413,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[936,21553,3312,7304,21554,61,60,573,80,15300],"class_list":["post-25412","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-apple","tag-cyberattack","tag-cybersecurity","tag-galaxy","tag-government-spyware","tag-ie","tag-ireland","tag-samsung","tag-technology","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/25412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=25412"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/25412\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/25413"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=25412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=25412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=25412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}