Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

176 Flaws Found in Samsung’s Preinstalled Apps, Including One-Click Account Takeover

What Happened

Security researchers at Oversecured identified 176 vulnerabilities across Samsung’s proprietary preinstalled mobile applications, apps shipped on every Galaxy device, not removable by users, and running outside the protection of Google Play Protect. The flaws, disclosed August 10, include a chain enabling one-click Samsung account takeover, remote code execution through malicious image files, and DNS manipulation capable of hijacking device network traffic. The vulnerable code sits in Samsung’s own system apps rather than in Android itself, meaning the exposure affects hundreds of millions of Galaxy devices worldwide regardless of Android security patch level. Samsung confirmed it fixed every issue Oversecured reported, with corrections rolling out through the company’s August security update alongside a separate set of 56 other patched vulnerabilities.

Why This Matters for Canadian Organizations

Samsung Galaxy ranks among the most widely used smartphone lines in Canada, spanning consumer devices, corporate-liable fleets, and bring-your-own-device programs across government, healthcare, and private sector organizations. Because these flaws live in apps users are unable to uninstall, patch compliance depends entirely on whether device owners install Samsung’s August firmware update, a step mobile device management teams should not assume happens automatically across a mixed fleet. Organizations handling personal information on Samsung devices under PIPEDA should treat unpatched fleets as a live exposure path for account takeover and data interception, not a theoretical risk.

What to Do

IT and mobile device management teams should push the August 2026 Samsung security update to all managed Galaxy devices immediately and verify update compliance rather than assuming automatic delivery. Organizations running bring-your-own-device programs should communicate the update urgency directly to staff given the account takeover and traffic hijacking risk involved. Full technical findings are available from SC Media and TechRepublic.

Enjoy this article? Don’t forget to share.