TouchWiz exploit factory resets some Samsung phones

  By Thom Holwerda, based on submission by bowkota - Posted on 2012-09-25 21:14:03 UTC at http://OSNews.com

On the same day I bought a brand new iMac and switched back to Mac (no joke [https://twitter.com/thomholwerda/status/250563964424056834]!), and teased the employees at the Apple retailer with my Galaxy SII, Samsung goes around and pulls something idiotic like this. TouchWiz, Samsung's Android skin, has a very severe flaw which passes digits along from JavaScript (via their modified browser) to the modified dialler, allowing your device to be factory reset (!) by just visiting a link [http://www.sammobile.com/2012/09/25/galaxy-s-ii-and-galaxy-advance-can-be-wiped-by-just-clicking-a-link/] - via NFC, QR, or plain. This doesn't affect all Samsung devices, but those that are affected are all TouchWiz devices. This just proves once again that you should either buy Nexus, or make the switch to Cyanogenmod (or any of the other AOSP-based ROMs).

Original story page here.

Copyright OSNews.com 1997-2006. All Rights Reserved. OSNews and the OSNews logo are trademarks of OSNews.
All trademarks, icons, and logos, shown or mentioned in this web site, are the property of their respective owners.
Reproduction of OSNews stories is granted only by explicitly receiving authorization from OSNews and if credit is given to OSNews.
Privacy statement   -   Notice to Bulk Emailers