Executive brief
A use-after-free vulnerability in the NPU driver of Samsung Mobile devices with Exynos chipsets allows for arbitrary memory writes and code execution. The flaw stems from improper handling of exceptional conditions and requires local access for exploitation.
Affected products
- Samsung Exynos Chipsets Prior to SMR Jan-2022 Release 1
- Google Android 9.0
- Google Android 10.0
- Google Android 11.0
- Google Android 12.0
Timeline
- 2022-01-10: disclosed: NVD Published Date
- 2022-01-01: patched: SMR Jan-2022 Release 1
- 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog