Executive brief
Samsung's Exynos mobile processors and modems contain a vulnerability in their radio resource control (RRC) handling that can be exploited by sending specially-crafted unauthenticated network messages. An attacker can cause the modem's baseband processor to crash, resulting in loss of cellular connectivity until the device reboots. This impacts any smartphone or connected device using the affected Exynos chips.
Technical details
The vulnerability exists in the NR RRC (5G Radio Resource Control) component of Samsung Exynos processors and modems. The root cause is improper validation of unauthenticated downlink RRC Setup messages, allowing an attacker to send a crafted RRC message that triggers a crash in the baseband processor. Attack vector is network-based (over-the-air from a cellular network or rogue base station) with no authentication or user interaction required. An attacker can cause a denial of service by crashing the modem, temporarily disabling cellular connectivity. The vulnerability affects Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000 processors and Modem 5300, 5400, and 5410. Patch availability is indicated by Samsung's security advisory publication.
Affected products
- Samsung Exynos 1080 <UNKNOWN>
- Samsung Exynos 2100 <UNKNOWN>
- Samsung Exynos 1280 <UNKNOWN>
- Samsung Exynos 2200 <UNKNOWN>
- Samsung Exynos 1330 <UNKNOWN>
- Samsung Exynos 1380 <UNKNOWN>
- Samsung Exynos 1480 <UNKNOWN>
- Samsung Exynos 2400 <UNKNOWN>
- Samsung Exynos 1580 <UNKNOWN>
- Samsung Exynos 2500 <UNKNOWN>
- Samsung Exynos W1000 <UNKNOWN>
- Samsung Modem 5300 <UNKNOWN>
- Samsung Modem 5400 <UNKNOWN>
- Samsung Modem 5410 <UNKNOWN>
Timeline
- 2025-10-22: disclosed: Reported date per Samsung advisory
- 2026-09-14: advisory: Published on NVD