Exploitation of a Samsung Galaxy Note 10+ Zero-Click RCE Bug via MMS

  Рет қаралды 124,808

Mateusz Jurczyk

Mateusz Jurczyk

4 жыл бұрын

Director's cut with a soundtrack: • [SOUNDTRACK] Exploitat... .
This video demonstrates the exploitation of a vulnerability in the custom Samsung Qmage image codec via MMS. The exploit proof-of-concept achieves remote code execution with no user interaction on a Samsung Galaxy Note 10+ phone running Android 10 (February 2020 patch level).
Vulnerabilities in the Qmage format were reported by the Google Project Zero team to Samsung in January 2020, and were addressed in the Samsung May 2020 Security Bulletin as SVE-2020-16747. The bugs were also collectively assigned CVE-2020-8899.
For more details, see:
* github.com/googleprojectzero/... - source code of the exploit.
* github.com/googleprojectzero/... - source code of the fuzzing harness used to identify the crashes.
* googleprojectzero.blogspot.co... - first of the MMS exploitation blog post series on the Project Zero blog.
* bugs.chromium.org/p/project-z... - the original in-depth report discussing the codec and security issues. It also includes an FAQ section outlining how the exploit works.
* security.samsungmobile.com/se... - Samsung Security Updates website.

Пікірлер
Cross-Site Request Forgery (CSRF) Explained
11:59
NahamSec
Рет қаралды 18 М.
Playing hide and seek with my dog 🐶
00:25
Zach King
Рет қаралды 33 МЛН
EVOLUTION OF ICE CREAM 😱 #shorts
00:11
Savage Vlogs
Рет қаралды 7 МЛН
Best Toilet Gadgets and #Hacks you must try!!💩💩
00:49
Poly Holy Yow
Рет қаралды 16 МЛН
Каха заблудился в горах
00:57
К-Media
Рет қаралды 5 МЛН
Zero Click Exploits Explained: Technical
10:23
RealTime Cyber
Рет қаралды 36 М.
everyone should test their code this way
8:34
Low Level Learning
Рет қаралды 79 М.
MAJOR EXPLOIT: This GIF can Backdoor any Android Phone (sort of)
12:00
iOS 18.1 Beta 1 Released - What's New? (Apple Intelligence)
15:53
Brandon Butch
Рет қаралды 90 М.
How SUDO on Linux was HACKED! // CVE-2021-3156
19:56
LiveOverflow
Рет қаралды 200 М.
Access Location, Camera  & Mic of any Device 🌎🎤📍📷
15:48
zSecurity
Рет қаралды 2,2 МЛН
ZeroLogon Exploit - Abusing CVE-2020-1472 (Way Too Easy!)
8:07
The Cyber Mentor
Рет қаралды 77 М.
Какой ноутбук взять для учёбы? #msi #rtx4090 #laptop #юмор #игровой #apple #shorts
0:18
Kumanda İle Bilgisayarı Yönetmek #shorts
0:29
Osman Kabadayı
Рет қаралды 2 МЛН
Looks very comfortable. #leddisplay #ledscreen #ledwall #eagerled
0:19
LED Screen Factory-EagerLED
Рет қаралды 4 МЛН
ОБСЛУЖИЛИ САМЫЙ ГРЯЗНЫЙ ПК
1:00
VA-PC
Рет қаралды 2,4 МЛН
Облачная память в iPhone? #apple #iphone
0:53
Не шарю!
Рет қаралды 127 М.