Google: Turn off VoLTE, Wi-Fi calling: severe Exynos modem vulnerabilities
9to5google.com
9to5google.com
* “Google Pixel devices received software updates in 2021 that automatically enabled VoLTE and removed the toggle.”> affected Pixel devices have already received a fix for CVE-2023-24033 in the March 2023 security update
[0] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
That line is carefully deceptive (lawyerly, even). Pixel 6 series have not yet received the March 2023 update.
https://9to5google.com/2023/03/06/march-google-pixel-update-...
> The four most severe of these eighteen vulnerabilities (CVE-2023-24033 and three other vulnerabilities that have yet to be assigned CVE-IDs) allowed for Internet-to-baseband remote code execution.
I wonder if you can disable LTE entirely and use an older standard.
https://en.wikipedia.org/wiki/2G#Past_2G_networks
YMMV in other countries of course, but many networks worldwide have already phased it out or are going to soon.
Turns out it was still locked to Telstra, they demanded *$100* to unlock the damn thing, even though they were turning off their 3G network anyway!
Unfortunately all the resources on hacking them has long since succumbed to linkrot, plus getting it hooked up over USB to an XP VM to try and unlock it that way seemed risky
[0] https://www.nperf.com/en/map/DE/-/187895.Telekom/signal/?ll=...
It's really baffling going here from Sweden where I'm starting to get 5G signal outside of core city areas, get 4G almost across the whole country with speeds of 50-100+Mbps, into the city centre of Berlin and there I fallback to 3G networks every 3rd/4th block walking.
Friends living there having terrible experiences with Telekom, almost no fiber available, etc.
Germany should enact something like this policy from here: https://pts.se/sv/bransch/internet/bredbandsstrategin/
A combination of toxic financial mindset (back in the early '00s, finance minister Hans Eichel wanted a "balanced" budget and auctioned off the frequency licenses for dozens of billions of euros, saddling the carriers with the debt instead of the government), thoroughly incompetent politicians (Merkel's "Das Internet ist für uns alle Neuland" is just the tip of the iceberg), NIMBYs (sadly, projects for tower construction routinely end up in death threats, and since 5G conspiracies also in actual terrorist attacks), and a populace that to a large degree just doesn't give enough of a fuck.
Japan has a nuclear accident, caused by a tsunami and partly due to known issues in the power plant. Merkel: "Oh no, let's close down all our nuclear power plants right away."
Merkel: "Oh, we need more energy now when we closed all our nuclear power plants. No problem, my buddy Putin has agreed to build a gas pipeline and provide us will all energy we need."
Putin has been rattling his weapons on the border or Ukraine since 2014. Merkel: "No problem, I called my buddy Putin and he said he will not attack. And by the way, no need for us to invest in our defense. We can continue to have Europe's weakest army per capita as Putin said he would not attack."
Migrant crisis in 2015. Merkel: "Everyone is welcome! Smugglers, just send them here, we will show our solidarity. Oh, we do not have enough schools, daycare, hospitals to take care of them all? Oh, many are lost teenagers and children without parents who took the chance now when we said everyone was welcome? Well, I guess they can earn their living selling drugs and sex."
> Japan has a nuclear accident, caused by a tsunami and partly due to known issues in the power plant. Merkel: "Oh no, let's close down all our nuclear power plants right away."
The entire country was calling for the dismantling of the NPPs, and no one sans the FDP and the Nazis cares much about them any more, not even their operators.. As for the gas pipeline, thank former Chancellor Schröder for that one.
> Putin has been rattling his weapons on the border or Ukraine since 2014. Merkel: "No problem, I called my buddy Putin and he said he will not attack. And by the way, no need for us to invest in our defense. We can continue to have Europe's weakest army per capita as Putin said he would not attack."
A valid point, but one shared across the political spectrum except the Greens - everyone else from left to right and the entire leadership of the German industry was blinded by the prospect of cheap energy. It is unfair IMO to single out Merkel there.
> Migrant crisis in 2015. Merkel: "Everyone is welcome! Smugglers, just send them here, we will show our solidarity. Oh, we do not have enough schools, daycare, hospitals to take care of them all? Oh, many are lost teenagers and children without parents who took the chance now when we said everyone was welcome? Well, I guess they can earn their living selling drugs and sex."
The first part is a blank reproduction of common Nazi conspiracy myths - the "pull factor" has been thoroughly disproven by now, even with the EU being a deadly fortress at its borders, still thousands of people attempt to cross the Mediterranean each year. The latter is one of the worst interpretations you can give - I'd put that one rather on bland disinterest and fear of the far-right, not an intention to push people off to selling drugs.
Nissan Leafs used AT&T and it was shut down at the end of 2016.
https://www.greencarreports.com/news/1102612_nissan-leaf-con...
Some areas were never built out with 2G but for the footprint that was always there they have not turned it off since it doesn't impact their spectrum very much. AT&T had poor spectrum planning so had to kill it off sooner to refarm the spectrum.
I was on an EDGE connection in Mexico just last month.
Careful if you put your SIM in a 3G only phone it may get blacklisted and you’ll need a new one.
Source: work at a carrier.
It’s (probably) not the same bug, but gives you an idea of the state of baseband security and the attack surface. The baseband is an ARM chip running an RTOS.
The security situation is not pretty. We have here an XML parser running in the baseband RTOS which has a stack overflow bug. There are no stack canaries and it looks like there’s no ASLR or even NX so they get trivial shellcode execution. Although they didn’t demonstrate persistence or AP compromise, I can’t imagine either of those would be hard from the privileged baseband, especially if the baseband drivers are as bad as the baseband firmware seems to be.
but this statement about baseband mitigations is only partially true. Huawei Balong platform has ASLR and stack canaries now (and some Infineon too I believe), and all baseband platforms are improving (even Mediatek). I didn't check Qualcomm lately, but they have a lot of similar protections now.
It's not trivial to do a pivot to AP on modern iPhones or Android phones (excluding some categories) - especially with PAC (and MTE coming).
But yeah, (Samsung) Shannon are an attractive target for attackers due to easily obtainable firmware, strings, DWARF (elf) firmware that you can find and relatively good debugging platform. The bugs are generally pretty low hanging too.
This isn't the same on Qualcomm platforms (Hexagon is notoriously hard to RE and debug), or the iPhone platforms.
> Mobile devices from Samsung, including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 and A04 series
...and many others.
And you seem to be missing that of Samsung puts out Qualcomm and Exynos versions of the same phone, sharing a model number with a phone on that list doesn't preclude it from being unaffected
There doesn't seem to be a user-friendly way to determine for sure which chipset you have. I think at the very least, Samsung ought to publish a little app for that immediately.
I don't think that's true, most of the reviews I read and watch on YouTube are made in Europe, UK, India.
When I worked at Samsung the reason was two-fold:
- There's a lot of internal competition, having two SoC suppliers for your flagship phones gives you leverage against both Qualcomm and in-house teams.
- Samsung treads lightly with US carriers. Using Qualcomm modems makes their certification process and field testing easier.
Oh, and stuff like qualcomm-specific hacks people were used to from Jail broken HTC devices (like phone call recording) not working. Final minority complaint was essentially based on qualcomm devices being more popular so you had more resources for custom roms, despite the fact that Exynos meant no need to do complicated jailbreak to load a custom rom.
Personally I found no issue with Exynos chips whatsoever. Always some of the fastest stuff I had in my hands.
Quite sad, really, because the space can use some competition.
As for weird GPUs, the S3C2410 (which got renamed as Exynos post-factum) used weird Samsung-designed GPU (doubly weird because it was GLES2-only GPU yet Samsung Android phones had GLES 1.1 only on it). Then first few generations (Galaxy S, S2, S3, S4) used PowerVR GPUs
The Hummingbird (Galaxy S and iPhone 4) had one too but arguably it became part of the Exynos line-up after the fact.
Funsies...
Sure, I recognize that I’m in the minority here, as someone who keeps his phone in airplane mode/wifi‐only mode all the time. But it doesn’t mean giving up much: most of my messaging (including replying to texts and checking voicemails) can be done from the browser, GPS navigation works fine without an internet connection (maps can be trivially preloaded), and when I desperately need internet access while driving I can pull into any Starbucks, McDonalds, or Walmart.
Mostly I do this for philosophical reasons (basically, purposely downgrading the importance of phone notifications relative to what activities I’m physically doing at a given time), but the security advantage of smaller attack surface is a benefit I hadn’t considered.
It was discontinued, assumedly for low sales as more and more people gave their kids either iPads or hand me down iPhones instead of buying iOS touches like they used to.
The modem in your phone isn't like a modem from the days of dialup, it's more like a cable modem. More often than not, the modem is its own entire microprocessor, ram, i/o, etc and then communicates with the device's CPU over a mixture of serial, i2c, spi, or other busses. For instance, in my Pinephone, the modem is a Qualcomm MDM9607, which is a single core arm cpu that has 256mb of ram and 256mb of nand on its package, it literally runs its own entire operating system (linux in its case) separate from what the CPU of the phone does.
This CPU can also have its own connection to the battery, which is how, for example, iPhones can remain 'findable' even when the phone's CPU is otherwise powered off and at rest. The modem sips at the little remaining power in the battery to power itself and the GPS chip to report the devices location.
As for 'removing the sim' that doesn't prevent the device from connecting to a network, just authenticating with it, typically. Your sim card is just a standard identifier and a little bit of storage that the modem can read and write to for things like storing contacts and SMS messages. All of which can be done in software as well (known as an eSIM these days).
Edit: Here's a link to the wiki page on the Pinephone's modem, just to give you an idea of what a cell phone's modem can be capable of, and keep in mind, it uses a rather old, outdated, and unpopular modem, other modems may have more features: https://wiki.pine64.org/wiki/PineModems
Don't know what happens when you put it in airplane mode, though.
The baseband processor also performs real time audio and noise cancelling functions.
So while I have had some decent luck with VOIP and dialer apps that live solely in the application layer, voice quality and noise cancelling, etc., may not ever be as good as what the RTOS in the baseband can provide.
But yep, would be nice if it was open source, although not sure how much that would help (only if sufficiently motivated auditors can be bothered to look at it). A bunch of baseband firmware is even encrypted on disk now (loaded into BB memory from the kernel)
Load that into Hexagoon IDA plugin and you'll see it's bog standard Hexagon for all the remote GSM/LT code that actually does stuff (similar to the project zero research). I haven't verified (and don't own a Pinephone) but most Quectel boards I've seen in the past do enforce signature validation, so binary patches are not easy.
>> Until security updates are available, users who wish to protect themselves from the baseband remote code execution vulnerabilities in Samsung’s Exynos chipsets can turn off Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings. Turning off these settings will remove the exploitation risk of these vulnerabilities.
> Google Pixel devices received software updates in 2021 that automatically enabled VoLTE and removed the toggle.
That's some great advice.
*#*#4636#*#*Hear me out: we've long known that the current state of modems running their own tiny buggy unpatched is with way too much access to the device has been bad but no one could do much about it. A severe exploit like this doing actual damage to users of flagship phones from google and Samsung might be enough to finally change that. Unless it hurts the bottom line of those companies severely they won't change it. I think they should have released the info to force them to.
I always thought it was ridiculous that LTE didn't come with a built-in voice mode that was just universally supported. VoLTE is more of an add on app on top of of data and a big cause of compatibility problems. It wasn't even finished when the rest of the LTE standard came out so many early phones came without support. And many still have to fall back to 3G during calls due to incompatibilities or networks blocking them due to "not invented here".
It's a mess compared to 2G/3G where you can just stick a sim card into any phone and know it will work just fine.
In a far future a data only network makes sense but we're not there yet and we definitely weren't when LTE was specced. Voice should have been an integral part of the standard.
> On Pixel phones, the main CVE-2023-24033 vulnerability was fixed with the March 2023 security patch that rolled out on Monday but should have come a week earlier.
> However, the Pixel 6, 6 Pro, and 6a have yet to see that March update and are currently vulnerable.
That means GrapheneOS is already protected against this vuln:
https://grapheneos.org/releases#2023031500
A tip of the hat (and my great thanks) to the GrapheneOS team!
https://www.fsf.org/blogs/community/replicant-developers-fin...
Have we surpassed incompetence and arrived at maliciousness yet?
Aren't modern phones supposedly securely separate the baseband from the OS (Android)? Does this mean that voice and data can be intercepted, but at least other data might be safe?
Also, aside from the surface level issues of a vuln like this, an attacker now has a serious foothold on the device, which is still very bad.
https://github.com/varunchitre15/MT6589_kernel_source/blob/m...
Look at the enable_mem_access_protection function.
Very kind of them to offer the freedom of choice to all those users who don't want to protect themselves!
This is why Wi-Fi Calling and VoLTE took off at roughly the same time. Once you can route calls as data, you can offer it over both cellular and Wi-Fi. (Wi-Fi Calling has an additional outer IPsec layer, but it is the same "guts" inside the tunnel.)
Doesn't 5G use VoNR? Or does VoNR imply the same SIP call format, but just over 5G instead of 4G?
That's qualcomm. The very idea of google's phone SoCs was to ditch qualcomm
This does not seem an unreasonable ask.
The kind of people with the resources to actively exploit this are the same kind of people who can compel the carriers to transmit whatever they want.
:/
- Turn off wifi calling
- Turn on airplane mode
And then ensure wifi is on and wait for the March security update.
> T2B3.230109.009.2023031500 (Pixel 6, Pixel 6 Pro, Pixel 6a) — 2023-03-05 Android patch level but only 2023-03-01 Pixel patch until a March stock OS release is published with updated firmware, etc. (marked as 2023-03-01 overall patch level in the OS)
Your baseband isn't protected. GrapheneOS patched Android, but the complete device set of images (firmware) is still vulnerable. That said, GrapheneOS does seem to implement its own additional baseband hardening.