ZeroHour

CVE-2021-25337

KEVmass

Improper Access Control in Samsung Mobile Clipboard Service Lets Apps Read/Write Local Files

CISA: Samsung Mobile Devices Improper Access Control Vulnerability

CVSS 3.1
7.1 high
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2021-25337 is an improper access control flaw (CWE-269) in the clipboard service of Samsung mobile devices, present in devices running security patch levels prior to Samsung's March 2021 Security Maintenance Release (SMR Mar-2021 Release 1). An untrusted application installed on the device can abuse the flaw to read or write certain local files that it should not be able to access, meaning a malicious or compromised app gains unauthorized access to sensitive data or can tamper with files on the device. The attack is local (AV:L) and requires user interaction, so exploitation requires a hostile app already running on the handset rather than a remote or network-based attack. All Samsung mobile devices on patch levels older than the March 2021 SMR are affected until they are updated. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-11-08, and related reporting indicates a surveillance vendor exploited Samsung phone zero-days, though no public proof-of-concept is known and ransomware use is unknown.

What to do: Update affected Samsung devices to SMR Mar-2021 Release 1 or a later monthly security maintenance release via the vendor's update mechanism (Settings > Software update), per CISA's required action to apply vendor updates. For fleets, check device security patch levels via MDM or the device's security patch version in Settings and confirm it is March 2021 or newer; treat any untrusted sideloaded apps on unpatched devices as potential local file-access risk.

Affected
Samsung Mobile Devices (Android)All Samsung mobile devices prior to SMR Mar-2021 Release 1 (security patch level earlier than March 2021)
Estimated exposure
masshundreds of millions of devices potentially affected (all Samsung phones/tablets not yet on the March 2021 SMR or later) — Samsung is the world's largest Android vendor with an active installed base on the order of a billion devices, and every unit still running a security patch level older than March 2021 was vulnerable until updated, so the potentially…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news