<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Potential samsung pass vulnerability in Mobile Apps &amp; Services</title>
    <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015010#M46426</link>
    <description>&lt;P&gt;What if you use only fingerprints for Samsung Pass?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Mar 2025 21:23:08 GMT</pubDate>
    <dc:creator>Sonora</dc:creator>
    <dc:date>2025-03-31T21:23:08Z</dc:date>
    <item>
      <title>Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014242#M46416</link>
      <description>Heyo, I've sorta just spotted something with samsung pass that is rather worrying in terms of authentication. I'd report this to samsung but I have a feeling live chat will have no idea what I'm talking about so I wouldn't know who to tell. First let me explain the situation.&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;You have samsung pass setup with the verification method set as fingerprints and the samsung pass pin. So you need a fingerprint to access it.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;Say someone watches you enter your device code. They take the device and try to access your samsung pass. They get stopped as fingerprint verification is required or the samsung pass pin is required. They only know your phone code as they saw you enter it. They cannot access samsung pass. This is how things should be. The issue...&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;They go to settings in samsung pass, they go to verification method, they enable "use screen lock". No fingerprint prompt appears, it just enables without question. They use that screen unlock code to access samsung pass. They see your samsung account password saved. They use that to remove the account from the device. They own the device now.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;Why can "use screen lock" be enabled without any kind of other authentication system? You should not be able to add another way to unlock it without proving you can use the other ways first. This is a rather large security hole.&lt;/DIV&gt;&lt;DIV&gt;I should also add, why can it be disabled in the first place if it can be enabled again at any moment?&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;I should add, this isn't some theoretical attack, the "identity check" feature in one ui 7 is designed specifically to stop this attack. But the loophole is samsung pass not authenticating some settings correctly.&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 Mar 2025 19:26:09 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014242#M46416</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T19:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014420#M46417</link>
      <description>Trying to report it as this makes samsung pass really insecure if someone happens to see your lock screen code. If "use screen lock" is disabled, it 100% should require fingerprint or the samsung pass pin to enable</description>
      <pubDate>Mon, 31 Mar 2025 19:41:07 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014420#M46417</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T19:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014433#M46418</link>
      <description>If they seen you enter your pin they could also goto settings - general management - reset - factory reset data lol, its lets you choose to use pin instead of fingerprint.</description>
      <pubDate>Mon, 31 Mar 2025 19:44:42 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014433#M46418</guid>
      <dc:creator>Abravenewworld</dc:creator>
      <dc:date>2025-03-31T19:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014437#M46419</link>
      <description>No that can't. You need the password of the samsung account to reset a device. Clearing fingerprints would make samsung pass only unlock with the samsjng pass pin. Using this issue, someone can get the samsung password from samsung pass, then use that to reset the device and compromise the account</description>
      <pubDate>Mon, 31 Mar 2025 19:45:11 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014437#M46419</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T19:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014545#M46421</link>
      <description>Just been updating the apps Samsung store</description>
      <pubDate>Mon, 31 Mar 2025 19:52:01 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014545#M46421</guid>
      <dc:creator>lance78</dc:creator>
      <dc:date>2025-03-31T19:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014610#M46422</link>
      <description>&lt;P&gt;I agree that it is a concern&amp;nbsp; and a security flaw in this ituation so worth reporting.&amp;nbsp; &amp;nbsp;An oveall review of the merits of Samsung Pass in this article.&amp;nbsp;&amp;nbsp;&lt;A href="https://www.allthingssecured.com/reviews/password-managers/samsung-pass/" target="_blank"&gt;https://www.allthingssecured.com/reviews/password-managers/samsung-pass/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 19:59:07 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014610#M46422</guid>
      <dc:creator>JAMES4578</dc:creator>
      <dc:date>2025-03-31T19:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014681#M46423</link>
      <description>To add to this. The process of resetting a phone needs the device code and the samsung account password. If you use samsung pass your passwords are in there. If you make samsung pass only unlock with a fingerprint or pin. The device code unlock method can be enabled without any checks. The setting shouldn't exist if disabling it means nothing. Since anyone could turn it on if they knew the device code.&lt;BR /&gt;&lt;BR /&gt;I'm guessing it is supposed to run a check but it just doesn't</description>
      <pubDate>Mon, 31 Mar 2025 20:23:17 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12014681#M46423</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T20:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015010#M46426</link>
      <description>&lt;P&gt;What if you use only fingerprints for Samsung Pass?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 21:23:08 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015010#M46426</guid>
      <dc:creator>Sonora</dc:creator>
      <dc:date>2025-03-31T21:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015100#M46427</link>
      <description>If you only use fingerprints for samsung pass, anyone can enable unlock with device code without using your fingerprint.&lt;BR /&gt;&lt;BR /&gt;Meaning it bypasses your fingerprint, as long as they know the device unlock code. This could be found by looking over your shoulder when you unlock your phone&lt;BR /&gt;&lt;BR /&gt;To be fully clear, that means the unlock to turn your phone on. They do not need to know the samsung pass pin or anything else.&lt;BR /&gt;&lt;BR /&gt;Enabling that setting should require your fingerprint or samsung pass pin. But it just doesn't.&lt;BR /&gt;&lt;BR /&gt;(This is an example, I of course would never do this)&lt;BR /&gt;So if I knew your phone pin and had the phone, I could get into your samsung pass without needing a fingerprint or the samsung pass pin by just enabling "use screen lock". With that access, I could find your samsung account details. Since your phone is a 2fa method, that would let me steal the samsung account. Then reset the phone using the password for the samsung account. I would have gained a new reset phone and locked you out of the account.&lt;BR /&gt;&lt;BR /&gt;If samsung added protection to this setting. I would have no way into your samsung pass meaning no account stealing and no phone reset. You would remotely track and lock the phone, protecting your data.&lt;BR /&gt;&lt;BR /&gt;Again, would never do this, do not do this. I think explaining the attack really shows my point</description>
      <pubDate>Mon, 31 Mar 2025 22:01:14 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015100#M46427</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T22:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015138#M46428</link>
      <description>I've mentioned this briefly in replies before but as a uni student studying computer networking and security, I really enjoy finding and documenting these kinda things. Hence the giant paragraphs. I pick samsung phones due to their security and knox, things other androids don't come close to</description>
      <pubDate>Mon, 31 Mar 2025 22:08:14 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015138#M46428</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T22:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015145#M46429</link>
      <description>&lt;P&gt;I never use device code for unlocking phone when someone looking. So, you can't access to my Samsung Pass.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 22:10:26 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015145#M46429</guid>
      <dc:creator>Sonora</dc:creator>
      <dc:date>2025-03-31T22:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015154#M46431</link>
      <description>That's not really my point. This whole thing started a few years ago. There's a trick where malicious individuals go to a bar, find someone, flirt or something. Get the person to request their phone number. The malicious person then goes to enter it into the phone, locks the phone, presses the fingerprint sensor a few times. Now the phone is locked and fingerprint is disabled. They then say the phone locked, the owner then enters the code to unlock the phone. The malicious person now has the phone and code. Then they can use the samsung pass issue.&lt;BR /&gt;&lt;BR /&gt;So yes normally you don't enter your code. But the bar scam thing is so common both apple and google added protection against it. Called identity check on android 15.&lt;BR /&gt;&lt;BR /&gt;Yes people aware won't enter or show their code. But it only takes one mistake. Samsung adding the proper checks to samsung pass would prevent the worse parts of the scam&lt;SPAN class="mobile-app-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Screenshot_20250331_232121_Settings_1000017432_1743459691.png"&gt;&lt;img src="https://eu.community.samsung.com/t5/image/serverpage/image-id/2806676i73E6200FF15E1401/image-size/small?v=v2&amp;amp;px=200" role="button" title="Screenshot_20250331_232121_Settings_1000017432_1743459691.png" alt="Screenshot_20250331_232121_Settings_1000017432_1743459691.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;</description>
      <pubDate>Mon, 31 Mar 2025 22:22:19 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015154#M46431</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T22:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015164#M46432</link>
      <description>&lt;P&gt;First mistake. Never give your phone to a stranger, enter the number yourself. It is very likely that your phone will not ask you for the device code, but your finger will unlock the phone. If you don't take some simple security steps like this yourself, it will be very difficult for someone to trick you. Caution is the mother of wisdom.&lt;span class="lia-unicode-emoji" title=":face_savoring_food:"&gt;😋&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 22:33:01 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015164#M46432</guid>
      <dc:creator>Sonora</dc:creator>
      <dc:date>2025-03-31T22:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015167#M46433</link>
      <description>You are right. But the majority of people don't do that. When drunk or out, they will just turn their phone to have someone enter a phone number.&lt;BR /&gt;&lt;BR /&gt;Pressing the wrong finger on the finger print sensor 3-5 times disables it, forcing the code.&lt;BR /&gt;&lt;BR /&gt;Also this is such a big issue google and apple made a specific security system to prevent it. So you can't just blow it off that easily. Yes you or I won't fall for it. But the fact that samsung pass has this security hole still exists</description>
      <pubDate>Mon, 31 Mar 2025 22:36:41 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015167#M46433</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-03-31T22:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015178#M46434</link>
      <description>&lt;P&gt;Ahh, those wonderful old days when there were no cell phones, so you still scheduled meetings and dates, and you wrote down phone numbers (not cell phones, but telephones) on a piece of paper or something. &lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't even like selfies. I have the same front camera as Mark Meta on his laptop &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;🤭&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 22:43:58 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12015178#M46434</guid>
      <dc:creator>Sonora</dc:creator>
      <dc:date>2025-03-31T22:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12019179#M46444</link>
      <description>Nice to see samsung is hopefully looking into this&lt;SPAN class="mobile-app-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Screenshot_20250401_184356_Samsung Members_1000017448_1743529447.png"&gt;&lt;img src="https://eu.community.samsung.com/t5/image/serverpage/image-id/2807551iB817A66B9B2599A4/image-size/small?v=v2&amp;amp;px=200" role="button" title="Screenshot_20250401_184356_Samsung Members_1000017448_1743529447.png" alt="Screenshot_20250401_184356_Samsung Members_1000017448_1743529447.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;</description>
      <pubDate>Tue, 01 Apr 2025 17:44:47 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/12019179#M46444</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-04-01T17:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/13076994#M51602</link>
      <description>&lt;P&gt;What is the safest setting to have on then, for a Samsung user?&lt;/P&gt;&lt;P&gt;Do I need to remove my screen lock, or change some setting so that no one can access the phone?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 10:37:53 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/13076994#M51602</guid>
      <dc:creator>ssnguser</dc:creator>
      <dc:date>2025-08-25T10:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Re: Re: Potential samsung pass vulnerability</title>
      <link>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/13078831#M51614</link>
      <description>There isn't anything you can do, so just carry on as normal.&lt;BR /&gt;&lt;BR /&gt;The issue only works if someone has your phone and knows your phone's code. So rare but not impossible.&lt;BR /&gt;&lt;BR /&gt;I personally have "use screen unlock" disabled in samsung pass. But someone can just enable it again, that's the issue&lt;BR /&gt;&lt;BR /&gt;Samsung could prevent it by putting a fingerprint check on that setting but hasn't yet</description>
      <pubDate>Mon, 25 Aug 2025 19:27:36 GMT</pubDate>
      <guid>https://eu.community.samsung.com/t5/mobile-apps-services/potential-samsung-pass-vulnerability/m-p/13078831#M51614</guid>
      <dc:creator>arianwen27</dc:creator>
      <dc:date>2025-08-25T19:27:36Z</dc:date>
    </item>
  </channel>
</rss>

