Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Google’s Project Zero Calls Urgent Attention To 18 Security Vulnerabilities Found In Samsung’s Exynos Chipsets
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > Google’s Project Zero Calls Urgent Attention To 18 Security Vulnerabilities Found In Samsung’s Exynos Chipsets
IT Security

Google’s Project Zero Calls Urgent Attention To 18 Security Vulnerabilities Found In Samsung’s Exynos Chipsets

Between late 2022 and early this year, Google's Project Zero found and reported 18 of these bugs in Samsung's Exynos cellular modem firmware

Editorial Desk
Last updated: March 20, 2023 2:18 pm
Editorial Desk
Share
SHARE

Critical security vulnerabilities expose Samsung’s Exynos chipset “Internet-to-baseband remote code execution” to attacks with no user interaction. Project Zero says an attacker only needs the victim’s phone number.

Contents
Assigned CVE numbersAffected phones Include

Project Zero team lead Tim Willis says his researchers reported at least 18 zero-day vulnerabilities in the Exynos modems produced by Samsung Semiconductor and used in the company’s flagship Galaxy devices.

He said in some cases, an attacker would only need to know the victim’s phone number to exploit the bugs in what is being described as “Internet-to-baseband remote code execution” attack vectors.

During the period spanning from late 2022 to early 2023, Google’s Project Zero discovered and reported 18 bugs in Samsung’s Exynos cellular modem firmware, “says Tim Willis, head of the team responsible for uncovering these vulnerabilities.

Of the 18 zero-day flaws, four have the potential to allow remote code execution from the internet to the baseband. The baseband, also known as the modem, typically possesses privileged, low-level access to all of the hardware, which means that exploiting flaws within its code could give an attacker complete control over the device or phone.

Currently, technical information regarding these vulnerabilities has been withheld to protect users of affected devices.

In a breakdown of the security flaws Willis said, “Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number.

“With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely,”

Assigned CVE numbers

One of these four severe bugs has been assigned a CVE number, and it’s tracked as CVE-2023-24033. The other three are awaiting bug IDs.

According to Willis Google would withhold details on four of the 18 vulnerabilities because of the severity of the issue and the risk that malicious actors could quickly reproduce the findings and create in-the-wild exploits.

These include CVE-2023-26072, CVE-2023-26073, CVE-2023-26074, CVE-2023-26075, CVE-2023-26076 and nine other vulnerabilities that haven’t yet been assigned identifiers.

Affected phones Include

 Samsung S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 and A04 mobiles; Vivo S16, S15, S6, X70, X60 and X30 series mobiles; Google’s Pixel 6 and Pixel 7 series; along with any wearables that use the Exynos W920 chipset; and any vehicles that use the Exynos Auto T5123 chipset.

Samsung has released a series of advisories outlining the Exynos chipsets impacted by these devastating vulnerabilities, which include mobile devices from Samsung, Vivo, and even Google’s prestigious Pixel 6/7 handsets.

The vulnerabilities have been identified as heap buffer overflows in the 5G MM message codec while decoding extended emergency lists, service area lists, and reserved options.

ByEditorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article NBN Co to cut around 500 staff redundant NBNCo To Make 500 Jobs – 10% of Staff Redundant By The End of June
Next Article Karen's job in customer service ChatGPT Why Karen’s job in customer service will survive ChatGPT – but creatives won’t
Samsung’s Exynos chipset “Internet-to-baseband Google

Tech Articles

Top Big Tech Companies 2026

The Big Tech Companies Actually Winning In 2026 — And Numbers That Prove It

Top tech companies in 2026 included AppLovin, AWS, Microsoft, Meta,…

May 20, 2026
Your Phone Is Spying on You and tracking location

Your Phone Is Spying on You — Here’s How to Stop It

Your phone is spying, tracking your location, searches, app activity,…

July 11, 2026
Why is APAC losing the war on digital fraud

Why APAC is Losing Ground In The Fight Against Digital Fraud

Why APAC is losing the war on digital fraud is…

May 6, 2026

Recent News

Cloudflare Integrates with Atlassian, Microsoft, and Sumo Logic
IT Security

Cloudflare Integrates Zero Trust Platform With Atlassian, Microsoft And Sumo Logic

4 Min Read
Hackers exploit bug in Elementor Pro WordPress plugin hack - Tech News
IT Security

Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin

4 Min Read
WordFence 116 Vulnerabilities Disclosed in 88 WordPress Plugins - tech news
IT Security

WordFence Discloses 116 Vulnerabilities Found In 88 WordPress Plugins

3 Min Read
Microsoft
IT Security

Microsoft Internal Communications Breach Raises Cybersecurity Concerns

3 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

July, 20, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?