Junglewise Threat Intelligence

CVE-2021-25337: Samsung Mobile Devices Improper Access Control Vulnerability

CVE-2021-25337 · Severity: critical · CVSS 7.1 · Exploited in the wild · Published 2022-11-08

Technologies: Samsung Mobile Devices. Vendors: Samsung.

Executive brief

Samsung mobile devices contain an improper access control vulnerability in the clipboard service. This flaw allows untrusted applications to read or write arbitrary local files, and has been observed being chained with other vulnerabilities in the wild.

Affected products

  • Samsung Android Prior to SMR Mar-2021 Release 1

Timeline

  • 2021-03-04: disclosed: NVD Published Date
  • 2022-11-08: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog

Related threats