CHKP Check Point Software Technologies Ltd.

Check Point Research Reveals Security Flaw that Leaves Android Smartphones Vulnerable to Advanced SMS Phishing Attacks

Check Point Research Reveals Security Flaw that Leaves Android Smartphones Vulnerable to Advanced SMS Phishing Attacks

Vulnerability impacts phones from Samsung, Huawei, LG, and Sony

SAN CARLOS, Calif., Sept. 04, 2019 (GLOBE NEWSWIRE) -- Check Point Research, the Threat Intelligence arm of (NASDAQ: CHKP), a leading provider of cyber security solutions globally, revealed a security flaw in Samsung, Huawei, LG, Sony and other Android-based phones that leaves users vulnerable to advanced phishing attacks.

The affected Android phones use over-the-air (OTA) provisioning, through which cellular network operators can deploy network-specific settings to a new phone joining their network. However, Check Point Research found that the industry standard for OTA provisioning, the Open Mobile Alliance Client Provisioning (OMA CP), includes limited authentication methods. Remote agents can exploit this to pose as network operators and send deceptive OMA CP messages to users. The message tricks users into accepting malicious settings that, for example, route their Internet traffic through a proxy server owned by the hacker.

Researchers determined that certain Samsung phones are the most vulnerable to this form of phishing attack because they do not have an authenticity check for senders of OMA CP messages. The user only needs to accept the CP and the malicious software will be installed without the sender needing to prove their identity.

Huawei, LG, and Sony phones do have a form of authentication, but hackers only need the International Mobile Subscriber Identity (IMSI) of the recipient to ‘confirm’ their identity. Attackers can obtain a victim’s IMSI in a variety of ways, including creating a rogue Android app that reads a phone’s IMSI once it is installed. The attacker can also bypass the need for an IMSI by sending the user a text message posing as the network operator and asking them to accept a pin-protected OMA CP message. If the user then enters the provided PIN number and accepts the OMA CP message, the CP can be installed without an IMSI.

“Given the popularity of Android devices, this is a critical vulnerability that must be addressed,” said Slava Makkaveev, Security Researcher at Check Point Software Technologies. “Without a stronger form of authentication, it is easy for a malicious agent to launch a phishing attack through over-the-air provisioning. When the user receives an OMA CP message, they have no way to discern whether it is from a trusted source. By clicking ‘accept’, they could very well be letting an attacker into their phone.”

The researchers disclosed their findings to the affected vendors in March. Samsung included a fix addressing this phishing flow in their Security Maintenance Release for May (SVE-2019-14073), LG released their fix in July (LVE-SMP-190006), and Huawei is planning to include UI fixes for OMA CP in the next generation of Mate series or P series smartphones. Sony refused to acknowledge the vulnerability, stating that their devices follow the OMA CP specification.

Check Point SandBlast Mobile prevents Man-in-the-Middle and phishing attacks, to help protect devices against such malicious OMA CP messages. To learn more, visit

For more details around this research, visit our blog at:

Follow Check Point Research via:

Blog:

Twitter:

About Check Point Research

Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber-attack data stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. The research team consists of over 100 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs.

About Check Point Software Technologies Ltd.

Check Point Software Technologies Ltd. () is a leading provider of cyber security solutions to governments and corporate enterprises globally.  Check Point’s solutions protect customers from 5th generation cyber-attacks with an industry leading catch rate of malware, ransomware and advanced targeted threats. Check Point offers a multilevel security architecture, “Infinity Total Protection with Gen V advanced threat prevention”, this combined product architecture defends an enterprises’ cloud, network and mobile devices. Check Point provides the most comprehensive and intuitive one point of control security management system. Check Point protects over 100,000 organizations of all sizes.

MEDIA CONTACT:INVESTOR CONTACT:
Jacinta PaulKip E. Meintzer
Check Point Software TechnologiesCheck Point Software Technologies
+1 650.628.2040

EN
04/09/2019

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Check Point Software Technologies Ltd.

Anish Jog ... (+4)
  • Anish Jog
  • Daniel Ives
  • Sam Brandeis
  • Steven Wahrhaftig

Good Results With a Key Few Quarters Ahead; Positive Mojo-PT to $210

A Closer Look at FY4Q25 (December) ResultsRevenueTotal revenue of $744.9 million (up 6% y/y) was in-line with the company’s guidance range of $700.0 million and $764.0 million and below the Street’s $746.3 million estimate primarily driven by demand for the company's emerging product portfolio whil

 PRESS RELEASE

Check Point Software Reports Fourth Quarter and 2025 Full Year Results

Check Point Software Reports Fourth Quarter and 2025 Full Year Results TEL AVIV, Israel, Feb. 12, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: CHKP), today announced its financial results for the fourth quarter and full year ended December 31, 2025. Fourth Quarter 2025 Highlights         Calculated Billings* reached $1,039 million, an 8 percent increase year over yearRemaining Performance Obligation (RPO)**: $2,728 million, an 8 percent increase year over yearTotal Revenues: $745 million, a 6 percent increase year over yearSecurity Subscription Revenues: $325 million, an 11 percent increase ye...

Anish Jog ... (+4)
  • Anish Jog
  • Daniel Ives
  • Sam Brandeis
  • Steven Wahrhaftig

ResearchPool Subscriptions

Get the most out of your insights

Get in touch