Junglewise Threat Intelligence

CVE-2022-22265: Samsung Mobile Devices Use-After-Free Vulnerability

CVE-2022-22265 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-09-18

Technologies: Samsung Mobile Devices. Vendors: Google, Samsung.

Executive brief

A use-after-free vulnerability in the NPU driver of Samsung Mobile devices with Exynos chipsets allows for arbitrary memory writes and code execution. The flaw stems from improper handling of exceptional conditions and requires local access for exploitation.

Affected products

  • Samsung Exynos Chipsets Prior to SMR Jan-2022 Release 1
  • Google Android 9.0
  • Google Android 10.0
  • Google Android 11.0
  • Google Android 12.0

Timeline

  • 2022-01-10: disclosed: NVD Published Date
  • 2022-01-01: patched: SMR Jan-2022 Release 1
  • 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats