Junglewise Threat Intelligence

CVE-2025-54601: Samsung Exynos Wi-Fi driver double free via race condition

CVE-2025-54601 · Severity: high · CVSS 7 · Published 2026-04-06

Technologies: Samsung Exynos 1280, Samsung Exynos 1480, Samsung Exynos 1380, Samsung Exynos W930, Samsung Exynos W920, Samsung Exynos 980, Samsung Exynos W1000, Samsung Exynos 1330, Samsung Exynos 1580, Samsung Exynos 850, Samsung Exynos 1080. Vendors: Samsung.

Executive brief

A security vulnerability has been identified in the Wi-Fi driver of several Samsung Exynos processors used in mobile phones and wearable devices like smartwatches. An attacker with local access to the device could exploit a flaw in how the system handles internal memory, potentially leading to a complete system crash or unauthorized access to sensitive data. This issue affects a wide range of Exynos chips, including the 980, 1080, and wearable-specific W-series processors.

Technical details

A race condition exists in the Wi-Fi driver of multiple Samsung Exynos mobile and wearable processors due to improper synchronization of a global variable. By concurrently invoking specific ioctl functions from multiple threads, a local attacker with low privileges can trigger a double-free vulnerability. This flaw (CWE-362) can result in memory corruption, leading to a denial of service (system crash) or potentially local privilege escalation. The vulnerability affects Exynos models 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, and wearable chips W920, W930, and W1000.

Affected products

  • Samsung Exynos 980
  • Samsung Exynos 850
  • Samsung Exynos 1080
  • Samsung Exynos 1280
  • Samsung Exynos 1330
  • Samsung Exynos 1380
  • Samsung Exynos 1480
  • Samsung Exynos 1580
  • Samsung Exynos W920
  • Samsung Exynos W930
  • Samsung Exynos W1000

Timeline

  • 2025-05-20: disclosed: Reported date according to vendor advisory
  • 2026-04-06: advisory: Initial NVD publication

References