|
|
|
|
|
by MishaalRahman
1302 days ago
|
|
1. We don't know what mitigation steps have been applied. However, it seems that at least some affected vendors are still signing their apps with compromised platform certs: https://www.apkmirror.com/?post_type=app_release&searchtype=... 2. Unknown. Could be multiple independent hacks of the OEM or an ODM, could be an insider, etc. 3. The attack vector is usually sideloading. |
|
On top of that, at least for the S21 series Samsung phones in their Common Criteria evaluated mode seemingly use the compromised 34df0e7a9f1cf1892e45c056b4973cd81ccf148a4050d11aea4ac5a65f900a42 certificate provided by earlier version 5.0.00.11 of com.samsung.android.svcagent[2]. I couldn't find a published applications list for S22 series phones in Common Criteria mode but suspect com.samsung.android.svcagent 7.0.00.1 from 2 September 2022 would be more recent anyway.
[1] https://apkcombo.com/svc-agent/com.samsung.android.svcagent/...
[2] https://www.google.com/search?q=inurl%3Adocs.samsungknox.com...