Security News > 2020 > February > Samsung cops to data leak after unsolicited '1/1' Find my Mobile push notification

Samsung cops to data leak after unsolicited '1/1' Find my Mobile push notification
2020-02-24 13:20

Samsung has admitted that what it calls a "Small number" of users could indeed read other people's personal data following last week's unexplained Find my Mobile notification.

Several Register readers wrote in to tell us that, after last Thursday's mystery push notification, they found strangers' personal data displayed to them.

Of potentially greater concern is the mystery 1/1 push notification from Find my Mobile, a baked-in app on stock Samsung Android distributions.

Stock apps cannot be uninstalled unless one effectively wipes the phone and installs a new operating system - unlocking the bootloader and reformatting with a new third-party, customised ROM. Samsung did not answer our questions as to how a "Disabled" app was able to receive and display push notifications.

A Samsung rep later told us, referring to the data breach on its UK customer account pages: "Less than 150 customers were affected, and we are contacting them directly."


News URL

https://go.theregister.co.uk/feed/www.theregister.co.uk/2020/02/24/samsung_data_breach_find_my_mobile/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Samsung 1725 182 413 285 88 968