Уровень 0 · материалов: 3
В кластер входят документы, описывающие технические недостатки в реализации безопасности мобильных устройств и интерфейсов, но не входят общие руководства по кибербезопасности.
Общие признаки: критические уязвимости безопасности, проблемы реализации в мобильных ОС, эксплуатация USSD-кодов, ошибки в прошивках производителей
Группа выше: Уязвимости финансовых и мобильных приложений
Смысл: The main idea is that a widespread vulnerability in several Android brands (HTC, Motorola, Sony, Samsung) allows USSD codes in links to execute without user consent, potentially leading to data loss due to manufacturers ignoring Google's security patches.
Multiple Android smartphone brands are vulnerable to remote USSD attacks that can delete data because manufacturers failed to apply available Google security patches.
Смысл: The main idea is that a specific security flaw in Samsung's TouchWiz interface allows remote data deletion via a simple HTML string, highlighting the risk of manufacturer-added software layers.
A security flaw in Samsung's TouchWiz interface allows a single line of HTML code to remotely wipe data from affected smartphones.
Смысл: The main idea is that compromising security protocols for the sake of user convenience (UX) leads to critical vulnerabilities, specifically regarding the use of USSD instead of SMS for 2FA and the removal of 2FA for 'trusted' devices.
A bank's decision to use USSD for 2FA and remember devices after first login created severe security holes that bypass phone lock screens and eliminate the second factor of authentication.