lg-g3-phone-006The LG G3 isn’t that old of a device. It was launched back in 2014 meaning that if we had to guess, there are still plenty of users out there on 24 month contracts that could still be holding onto it. If you do own the device, then this is something to take note of, especially since it is regarding a security vulnerability on the device.

Advertising

As reported by The Register, this was discovered by security firms BugSec and Cynet who recently came across a vulnerability found on the phone, and it seems that this vulnerability was created by LG themselves through one of the phone’s features: Smart Notice. The bug is dubbed SNAP and basically what it does is that it could potentially allow malicious hackers to run phishing scams, access private data, and potentially cause the device to crash.

Apparently this is because LG had apparently forgotten to validate user-submitted data, which in turn allows these attacks to go through unfettered. According to Idan Cohen, BugSec’s CTO, “The vulnerability might be used to steal data. We don’t know for sure this has actually happened and we haven’t seen any malware that uses it. One thing is clear: This vulnerability is not just theoretical.”

The good news is that after being contacted by BugSec, LG then released a patch for Smart Notice which should address the problem. So if you have noticed that there is a patch waiting for you, then you should probably go ahead and do it. Note that because this seems to be a feature-specific problem, only the LG G3 out of all of LG’s devices are affected by this problem. You can check out the vulnerability being exploited in the demo video below.

Filed in Cellphones. Read more about , and .

5.5"
  • 2560x1440
  • IPS LCD
  • 534 PPI
13 MP
  • f/2.4 Aperture
  • OIS
3000 mAh
  • Removable
  • No Wireless Charg.
2GB RAM
  • Snapdragon 801
  • MicroSD
Price
~$380 - Amazon
Weight
149 g
Launched in
2014-05-27
Storage (GB)
  • 16
Related Articles on Ubergizmo