Skip to main content

Firefox FindMyDevice Service Lets Hackers Wipe or Lock Phones, Change PINs

  • October 21, 2015
  • 0 replies
  • 2 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
By Catalin Cimpanu    21 Oct 2015
 

A variation on an older Samsung Find My Mobile attack

 
Vulnerabilities in Mozilla's Find My Device service enabled hackers to carry out attacks that locked the screens of smartphones running Firefox OS, change PINs, make the devices ring, and even wipe all data with only a few clicks.
 
The Firefox Find My Device service allows users who've lost their Firefox OS phone to lock it or see its location on a map and retrieve it or direct law enforcement to the thief's location. The service is extremely usable and is a similar feature to what Apple has been offering for years for iPhone users.
 

A variation of CVE-2014-8346 that affected the Samsung Find My Mobile service

 
Egyptian security researcher Mohamed A. Baset is "guilty" of discovering this flaw, which seems to be a variation (but it's not) of CVE-2014-8346, a security vulnerability that affected the Samsung Find My Mobile service.
 
Full Article