Executive brief
A critical vulnerability has been identified in the cellular modem and processors used in many Samsung mobile and wearable devices. The flaw exists in how the device handles incoming text messages, potentially allowing a remote attacker to take control of the device or disrupt its operations simply by sending a malicious message. This could lead to the theft of sensitive data, unauthorized tracking, or a complete loss of device functionality.
Technical details
A stack-based buffer overflow (CWE-121) exists in the SMS implementation of several Samsung Exynos Mobile Processors, Wearable Processors, and Modems. The vulnerability is triggered during the parsing of SMS RP-DATA (Relay Protocol Data) messages. An unauthenticated remote attacker can exploit this by sending a specially crafted SMS message over the cellular network. Successful exploitation could lead to remote code execution within the modem or processor context, potentially bypassing security boundaries (S:C) and resulting in a total compromise of confidentiality, integrity, and availability. Affected chipsets include Exynos 980 through 2500, wearable series W920-W1000, and Modems 5123, 5300, and 5400.
Affected products
- Samsung Exynos 980
- Samsung Exynos 990
- Samsung Exynos 850
- Samsung Exynos 1080
- Samsung Exynos 2100
- Samsung Exynos 1280
- Samsung Exynos 2200
- Samsung Exynos 1330
- Samsung Exynos 1380
- Samsung Exynos 1480
- Samsung Exynos 2400
- Samsung Exynos 1580
- Samsung Exynos 2500
- Samsung Exynos 9110
- Samsung Exynos W920
- Samsung Exynos W930
- Samsung Exynos W1000
- Samsung Exynos Modem 5123
- Samsung Exynos Modem 5300
- Samsung Exynos Modem 5400
Timeline
- 2025-06-10: disclosed: Reported date according to vendor advisory
- 2026-04-06: advisory: Initial NVD publication date