November 5, 2015 By Shane Schick 2 min read

The team at Google charged with looking for security risks may be called Project Zero, but its investigation into the Galaxy S6 Edge has revealed a much higher number of potential vulnerabilities.

According to a post issued by Project Zero earlier this week, an audit of Samsung Galaxy S6 Edge smartphones have at least 11 issues described as high-impact. These problems include security holes in the gallery app and email client. While original equipment manufacturers (OEMs) theoretically take a lot of time and effort to test their products for security risks prior to release, the Google researchers uncovered the flaws in just one week.

The Verge suggested that to some extent, the security issues in products like the Galaxy S6 Edge are to be expected, given the cutthroat competition among manufacturers and the challenge of standing out in the Android market. It remains to be seen whether BlackBerry, which is expected to launch its first Android device called the Priv, will do any better in keeping cyberthreats at bay.

Fortunately, Samsung is already working to make its products safer for consumers and businesses. Many of the script injection problems, JavaScript vulnerabilities and other flaws have already been patched, BetaNews reported. While at least three issues still needed to be dealt with at press time, Samsung received kudos from Project Zero for the speed of its response to the findings.

Of course, Android security has been an ongoing concern, particularly among enterprise users, which is probably why Google and Samsung committed to monthly updates earlier this year, Mashable pointed out. One of the interesting things about Project Zero’s work is the seemingly straightforward approach it has to finding the flaws: Teams attempt to gain access to unauthorized permissions through an app on Google Play or by injecting code into a phone and trying to maintain it, even if the devices were wiped clean.

The Telegraph noted that besides Samsung, a number of other OEMs are all expected to release updates of their devices supporting the latest version of Android. These include LG, HTC and Sony. Here’s hoping the next generation of Galaxy S6 Edge devices are a little more secure.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today