
Samsung's Find My Mobile service has come under fire by NIST and security researcher Mohamed Baset regarding an exploit that allows attackers to remotely lock, ring or wipe Samsung devices. Baset points to a vulnerability in Samsung's service that doesn't validate the lock code information it receives, allowing an attacker to flood the device with network traffic and do their bidding. No word from Samsung on a patch, but for now we recommend disabling the service until they address the security issue.
Update:
Samsung issued a statement to us and it looks like it only affected the Web interface, not mobile devices. Furthermore, they patched the Web UI on October 13.
The reported issue occurred on the Find My Mobile Web site, and was not a problem on any mobile device. This Web UI was fixed with a patch update on October 13.
Source: Engadget