Junglewise Threat Intelligence

CVE-2023-21492: Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability

CVE-2023-21492 · Severity: critical · CVSS 4.4 · Exploited in the wild · Published 2023-05-19

Technologies: Samsung Mobile Devices. Vendors: Samsung.

Executive brief

Samsung mobile devices running Android 11, 12, and 13 leak kernel pointers into log files. This vulnerability allows a privileged local attacker to bypass Address Space Layout Randomization (ASLR) protections.

Affected products

  • Samsung Android 11, 12, 13 (prior to SMR May-2023 Release 1)

Timeline

  • 2023-05-19: disclosed
  • 2023-05-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-19: exploited: Reported as exploited in the wild in the advisory.
  • 2023-05-01: patched: SMR May-2023 Release 1

Related threats