Cyber Security News

Samsung Galaxy S24 Vulnerability Let Create Arbitrary Files on Affected Installations

A significant vulnerability in Samsung Galaxy S24 devices that allows network-adjacent attackers to create arbitrary files on affected installations. 

The flaw, identified as CVE-2024-49421, was publicly announced on April 9, 2025, as part of the Pwn2Own competition findings.

The vulnerability, tracked as ZDI-25-229 (ZDI-CAN-25650), received a CVSS score of 5.9 (AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L), indicating a medium-to-high severity issue. 

Security researcher Ken Gannon of NCC Group (@yogehi) discovered the directory traversal vulnerability in Samsung’s Quick Share feature, which allows users to easily share files between devices.

Critical Security Flaw in Quick Share Application

According to the Zero Day Initiative advisory, the vulnerability provides attackers with network access to create arbitrary files on affected installations of Samsung Galaxy S24.

An attacker must first gain access to the target device to undertake any activity.  The issue results from the lack of proper validation of a user-supplied path prior to using it in file operation.

“The specific flaw exists within the Quick Share application. An attacker can leverage this vulnerability to create files in the context of the current user”, reads the advisory.

The technical details reveal that the vulnerability stems from improper path validation, enabling attackers to manipulate file operations through the Quick Share Agent. 

The vulnerability affects explicitly Quick Share Agent versions prior to 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14.

To exploit this vulnerability, an attacker needs to be network-adjacent to the target device, meaning they must be on the same network or in close physical proximity. 

While this limits the attack scope, it still presents significant risks in public spaces like cafes, airports, or office environments. The directory traversal vulnerability could allow malicious actors to create files in arbitrary locations with the permissions of the current user. 

This could potentially lead to the installation of malicious applications, data manipulation, or system instability.

The summary of the vulnerability is given below:

Risk FactorsDetails
Affected ProductsSamsung Galaxy S24 series
ImpactAllows network-adjacent attackers to create arbitrary files via directory traversal in Quick Share
Exploit Prerequisites
Attacker must have network proximity and initial access to the device
CVSS 3.1 Score5.9 (Medium)

Patch Released – Time to Update!

Samsung has acknowledged the vulnerability and issued an update to correct it as part of their security maintenance schedule. 

“Samsung has issued an update to correct this vulnerability,” confirms the advisory

The fix is included in the December 2024 security maintenance release, which users are strongly encouraged to install.

The vulnerability was reported to Samsung on December 2, 2024, with a coordinated public release of the advisory occurring on April 9, 2025. 

This follows standard responsible disclosure protocols, giving Samsung time to develop and deploy a patch before public disclosure.

This is not the first security concern affecting Samsung’s file-sharing capabilities. Earlier this year, Google patched a similar Quick Share vulnerability (CVE-2024-10668) that could enable denial-of-service attacks or unauthorized file delivery. 

That vulnerability was a bypass for previously fixed issues in the QuickShell vulnerabilities disclosed in August 2024.

Samsung has been addressing multiple security vulnerabilities across its product line. The April 2025 security patch fixed over 60 issues, including 4 critical vulnerabilities.

Galaxy S24 users should verify they have the latest security updates installed by checking Settings > Software Update > Download and Install. 

Security experts recommend keeping automatic updates enabled and exercising caution when using Quick Share with unknown devices or on public networks.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago