November 5, 2015 By Shane Schick 2 min read

The team at Google charged with looking for security risks may be called Project Zero, but its investigation into the Galaxy S6 Edge has revealed a much higher number of potential vulnerabilities.

According to a post issued by Project Zero earlier this week, an audit of Samsung Galaxy S6 Edge smartphones have at least 11 issues described as high-impact. These problems include security holes in the gallery app and email client. While original equipment manufacturers (OEMs) theoretically take a lot of time and effort to test their products for security risks prior to release, the Google researchers uncovered the flaws in just one week.

The Verge suggested that to some extent, the security issues in products like the Galaxy S6 Edge are to be expected, given the cutthroat competition among manufacturers and the challenge of standing out in the Android market. It remains to be seen whether BlackBerry, which is expected to launch its first Android device called the Priv, will do any better in keeping cyberthreats at bay.

Fortunately, Samsung is already working to make its products safer for consumers and businesses. Many of the script injection problems, JavaScript vulnerabilities and other flaws have already been patched, BetaNews reported. While at least three issues still needed to be dealt with at press time, Samsung received kudos from Project Zero for the speed of its response to the findings.

Of course, Android security has been an ongoing concern, particularly among enterprise users, which is probably why Google and Samsung committed to monthly updates earlier this year, Mashable pointed out. One of the interesting things about Project Zero’s work is the seemingly straightforward approach it has to finding the flaws: Teams attempt to gain access to unauthorized permissions through an app on Google Play or by injecting code into a phone and trying to maintain it, even if the devices were wiped clean.

The Telegraph noted that besides Samsung, a number of other OEMs are all expected to release updates of their devices supporting the latest version of Android. These include LG, HTC and Sony. Here’s hoping the next generation of Galaxy S6 Edge devices are a little more secure.

More from

Apple Intelligence raises stakes in privacy and security

3 min read - Apple’s latest innovation, Apple Intelligence, is redefining what’s possible in consumer technology. Integrated into iOS 18.1, iPadOS 18.1 and macOS Sequoia 15.1, this milestone puts advanced artificial intelligence (AI) tools directly in the hands of millions. Beyond being a breakthrough for personal convenience, it represents an enormous economic opportunity. But the bold step into accessible AI comes with critical questions about security, privacy and the risks of real-time decision-making in users’ most private digital spaces. AI in every pocket Having…

Government cybersecurity in 2025: Former Principal Deputy National Cyber Director weighs in

4 min read - As 2024 comes to an end, it’s time to look ahead to the state of public cybersecurity in 2025.The good news is this: Cybersecurity will be an ongoing concern for the government regardless of the party in power, as many current cybersecurity initiatives are bipartisan. But what will government cybersecurity look like in 2025?Will the country be better off than they are today? What are the positive signs that could signal a good year for national cybersecurity? And what threats should…

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today