Junglewise Threat Intelligence

CVE-2021-25394: Samsung Mobile Devices Race Condition Vulnerability

CVE-2021-25394 · Severity: critical · CVSS 6.4 · Exploited in the wild · Published 2023-06-29

Technologies: Google Android, Samsung Mobile Devices. Vendors: Google, Samsung.

Executive brief

A race condition vulnerability in the Samsung MFC charger driver leads to a use-after-free condition. This flaw allows an attacker with compromised radio privileges to perform arbitrary memory writes on affected Samsung mobile devices.

Affected products

  • Samsung Android prior to SMR MAY-2021 Release 1
  • Google Android 8.1, 9.0, 10.0, 11.0

Timeline

  • 2021-05-01: patched: SMR MAY-2021 Release 1
  • 2021-06-11: disclosed: NVD Published Date
  • 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-29: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats