Junglewise Threat Intelligence

CVE-2021-25369: Samsung Mobile Devices Improper Access Control Vulnerability

CVE-2021-25369 · Severity: critical · CVSS 6.2 · Exploited in the wild · Published 2022-11-08

Technologies: Samsung Mobile Devices, Google Android. Vendors: Samsung, Google.

Executive brief

Samsung mobile devices using Mali GPUs contain an improper access control vulnerability in the sec_log file. This flaw allows the exposure of sensitive kernel information to userspace and has been observed being chained with other vulnerabilities in the wild.

Affected products

  • Google Android 8.0, 8.1, 9.0, 10.0
  • Samsung Android Prior to SMR MAR-2021 Release 1

Timeline

  • 2021-03-26: disclosed: NVD Published Date
  • 2021-03-01: patched: SMR MAR-2021 Release 1
  • 2022-11-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats