---
title: "Google Discovers Samsung and LG Phones Are Vulnerable Due to Leaked Certificates."  
description: "Many flaws in Android's platform signing keys trust process were discovered by Google's Android Partner Vulnerability Initiative."  
author: "Muskan Singh"  
published: 2022-12-05  
canonical: https://www.mindstick.com/news/2494/google-discovers-samsung-and-lg-phones-are-vulnerable-due-to-leaked-certificates  
category: "mobile/tablet"  
tags: ["android layout", "mobile", "technology", "technology news", "samsung"]  
reading_time: 2 minutes  

---

# Google Discovers Samsung and LG Phones Are Vulnerable Due to Leaked Certificates.

- Ukasz Siewierski, a Google employee, discovered the vulnerability.
- It is said that Google has released a statement assuring [consumers](https://answers.mindstick.com/qa/43079/how-did-the-national-consumers-league-try-to-improve-the-lives-of-workers) of their protection.
- The hash files for the virus samples have been published online.

In a significant security leak admission, Google's Android Partner Vulnerability [Initiative](https://answers.mindstick.com/qa/98030/what-is-the-smile-75-initiative) has revealed a new important vulnerability that has impacted Android handsets from well-known manufacturers like Samsung and LG, among others.

Because the signing keys used by Android OEMs were made public, [malicious](https://www.mindstick.com/blog/303209/discover-effective-strategies-for-recognizing-and-dodging-malicious-urls) software or fraudulent apps might pass for 'trusted' ones. Following an earlier [discovery](https://www.mindstick.com/interview/34385/understanding-the-discovery-phase-in-software-development-part-1) of the problem in May of this year, some businesses, including [**Samsung**](https://www.mindstick.com/news/2428/samsung-galaxy-s23-ultra-display-could-offer-up-to-2-200-nits-peak-brightness), took action to close the vulnerability.

Google employee ukasz Siewierski discovered the security hole (via Esper's Mishaal Rahman). Through his tweets, Sirwierski disclosed how Android Trojan apps had been signed using platform certificates. The issue is caused by a flaw in the crucial trusting mechanism of the Android platform, which might be exploited by malicious attackers.

The shared user ID system for Android automatically trusts any [application](https://www.mindstick.com/articles/12824/calculator-application-in-android) that uses a platform signing key that is legitimate and is used to sign the core system applications. However, since the [**Android OEMs' platform**](https://www.mindstick.com/news/2419/samsung-developing-new-xisocell-image-sensors) signing keys have been made public, malware authors now have access to system-level rights on a target device.

The attacker would have access to all [user data](https://www.mindstick.com/forum/160424/how-do-bearer-tokens-ensure-the-security-and-confidentiality-of-user-data) on that particular device, just like with another system app from the manufacturer approved with the same [certificate](https://www.mindstick.com/blog/122/viewing-client-certificate). Another worrying element of the vulnerability is that it doesn't always require a user to install a brand-new or 'unknown' programme. Potentially, widely used, respected programmes like the Bixby app for Samsung smartphones might be signed using the platform keys that were hacked.

If a user downloaded such an app from a third-party website, they wouldn't get a warning throughout the [installation process](https://answers.mindstick.com/blog/338/basic-requirements-and-ollama-installation-process) because the certificate would match the one on their machine. **Google, however, has not made clear in its public statement which OEMs or devices are currently affected by the significant vulnerability.** Nevertheless, a list of sample malware files is provided in the publication.

---

Original Source: https://www.mindstick.com/news/2494/google-discovers-samsung-and-lg-phones-are-vulnerable-due-to-leaked-certificates

Copyright © MindStick Software Pvt. Ltd. This Markdown version is provided for developers, AI systems, and offline reading.
