Mobile

A Samsung Texting App bug is sending random photos to contacts

Some Samsung devices are randomly sending photos taken with the camera to contacts in the address book without permission.

Do you have a Samsung smartphone? There is something you need to know.

Some devices are randomly sending photos taken with the camera to contacts in the address book without permission.

The problem affected Galaxy S9 and S9+ devices, but we cannot exclude that other devices may have been affected.

The news was first reported by Gizmodo, several users reported the anomalous behavior on Reddit and the company official forums.

“Sending pictures to others is one of the most basic functions of a smartphone, but when your phone’s texting app starts randomly pushing out photos without your knowledge, you got a problem..” reported Gizmodo

“And unfortunately, according to a smattering of complaints on Reddit and the official Samsung forums, it seems that’s exactly what happened to a handful of Samsung phone users, including owners of late model devices such as the Galaxy Note 8 and Galaxy S9.”

One user explained that his phone sent all his photos to his girlfriend over the night, but there was no record of it on his messages app. The expert discovered that there was a record of this activity on the mobile logs.

“Last night around 2:30 am, my phone sent her my entire photo gallery over text but there was no record of it on my messages app. However, there was record of it on tmobile logs. Why would this happen?” wrote the user on Reddit.

The unwanted messages were sent out via the Samsung Messages app, some users discovered the issue after they received a response from the recipients that received the photos.

A Samsung confirmed it is aware of the reports” and that its technical staff is investigating the problem.

Below the list of problems observed since the RCS Messaging was enabled and occurs with the SCHEDULED TEXT feature.

  • Scheduled Messages are sent prematurely
  • Scheduled text Messages end up in WRONG threads
  • Messaging incorrectly displays scheduled messages as “sent” when, in fact, the other party has not received them.

Clearly many users are speculating this glitch was introduced with the push of RCS messaging updates by telco carriers.

As a temporary measure, Samsung owners can revoke Samsung Message’s permissions to access storage (Settings -> Apps -> Samsung Messages -> Permissions -> Storage).

Concerned customers are encouraged to contact us directly at 1-800-SAMSUNG

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – mobile, bug)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

MITRE revealed that nation-state actors breached its systems via Ivanti zero-days

The MITRE Corporation revealed that a nation-state actor compromised its systems in January 2024 by…

14 hours ago

FBI chief says China is preparing to attack US critical infrastructure

China-linked threat actors are preparing cyber attacks against U.S. critical infrastructure warned FBI Director Christopher…

1 day ago

United Nations Development Programme (UNDP) investigates data breach

The United Nations Development Programme (UNDP) has initiated an investigation into an alleged ransomware attack…

1 day ago

FIN7 targeted a large U.S. carmaker with phishing attacks

BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large…

2 days ago

Law enforcement operation dismantled phishing-as-a-service platform LabHost

An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost.…

2 days ago

Previously unknown Kapeka backdoor linked to Russian Sandworm APT

Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since…

2 days ago

This website uses cookies.