TouchWiz exploit factory resets some Samsung phones

On the same day I bought a brand new iMac and switched back to Mac (no joke!), and teased the employees at the Apple retailer with my Galaxy SII, Samsung goes around and pulls something idiotic like this. TouchWiz, Samsung’s Android skin, has a very severe flaw which passes digits along from JavaScript (via their modified browser) to the modified dialler, allowing your device to be factory reset (!) by just visiting a link – via NFC, QR, or plain. This doesn’t affect all Samsung devices, but those that are affected are all TouchWiz devices. This just proves once again that you should either buy Nexus, or make the switch to Cyanogenmod (or any of the other AOSP-based ROMs).

22 Comments

  1. 2012-09-25 9:24 pm
    • 2012-09-25 9:28 pm
      • 2012-09-26 5:11 am
      • 2012-09-26 6:41 am
  2. 2012-09-25 9:36 pm
    • 2012-09-25 9:45 pm
      • 2012-09-25 9:53 pm
        • 2012-09-25 10:01 pm
        • 2012-09-25 10:32 pm
    • 2012-09-25 9:49 pm
      • 2012-09-26 8:04 am
  3. 2012-09-25 10:00 pm
    • 2012-09-26 1:15 am
      • 2012-09-26 8:06 am
    • 2012-09-26 10:16 am
  4. 2012-09-26 12:34 am
    • 2012-09-26 7:56 am
      • 2012-09-26 12:26 pm
        • 2012-09-26 12:35 pm
          • 2012-09-26 12:43 pm
  5. 2012-09-26 7:49 am
  6. 2012-09-26 2:09 pm