Junglewise Threat Intelligence

CVE-2021-25395: Samsung Mobile Devices Race Condition Vulnerability

CVE-2021-25395 · Severity: critical · CVSS 6.4 · Exploited in the wild · Published 2023-06-29

Technologies: Samsung Mobile Devices. Vendors: Samsung.

Executive brief

A race condition in the Samsung MFC charger driver leads to a use-after-free vulnerability. Local attackers with compromised radio privileges can exploit this to bypass signature checks or perform unauthorized writes.

Affected products

  • Samsung Android prior to SMR MAY-2021 Release 1

Timeline

  • 2021-05-01: patched: SMR MAY-2021 Release 1
  • 2021-06-11: disclosed: NVD Published Date
  • 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-29: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats