The 2016 Pwnie Nominee For Best Server-Side Bug

Samsung Galaxy Edge Baseband Stack Overflow (CVE-2015-8546)

Credit: Daniel Komaromy and Nico Golde

Basebands are basically just the crappy embedded system embedded within the crappy embedded system that you call your phone. Daniel and Nico found an exploitable stack buffer overflow in Samsung’s “Shannon” baseband and exploited it from their OpenBTS rogue base station to gain code exec and redirect the victim’s phone calls. In short, THEY RAINED THE HACKS DOWN FROM THE SKY!

Samsung Galaxy Edge Baseband Stack Overflow

(CVE-2015-8546)