Original topic:

January 2023 update fixes Samsung Knox and Secure Folder flaws

(Topic created on: 01-04-2023 09:29 PM)
301 Views
TheFastestIndian
Expert Level 5
Options
Tech Talk

image

An out-of-bound read vulnerability was patched with proper boundary check logic. An improper input validation vulnerability in TelephonyUI that would allow attackers to configure “Preferred Call” was fixed, and the patch removed unused code.

A hardcoded encryption key vulnerability in NFC was fixed by adding proper usage of random private key API to prevent key exposure. And an improper access control vulnerability in telecom applications was fixed with access control logic to prevent sensitive information leaks.

The January 2023 security patch also fixes a Knox Service vulnerability concerning Permissions or Privileges. The patch also adds restrictions that lock the Secure Folder container when PIP is closed. In other words, the vulnerability allowed the Secure Folder container to remain unlocked under certain conditions.
5 Comments
mctr
Beginner Level 2
Tech Talk
Finger print lock
0 Likes
garvitgoel_
Active Level 8
Tech Talk
Have they patched the vulnerability which lead to h.a.c.k in 50 sec?
Tech Talk
No news on that but should have been patched
0 Likes
ashishj22
Beginner Level 2
Tech Talk
Hii
I forgot my secure folder pattern and I attempted all my chances and now my secure folder says "your samsung account has been changed. To enable secure folder, sign in as ashishj2212@gmail.com and reset your secure folder lock" but when I sign in as ashishj2212@gmail.com it says it has already exists
0 Likes
Tech Talk
Please check with Samsung customer care
0 Likes