ZeroHour

CVE-2021-25369

KEVmass1

Improper Access Control in Samsung Mobile sec_log Exposes Kernel Information

CISA: Samsung Mobile Devices Improper Access Control Vulnerability

CVSS 3.1
5.5 medium
EPSS
1%p64
Published
()
KEV added
AI analysis

CVE-2021-25369 is an improper access control flaw (CWE-200) in the sec_log file on Samsung mobile devices, which exposes sensitive kernel information to userspace on devices prior to the March 2021 Samsung security release (SMR MAR-2021 Release 1). It is triggered locally: a low-privileged user or app on the device can read the insufficiently protected sec_log file (local attack vector, no user interaction required). An attacker gains disclosure of sensitive kernel information; the standalone impact is moderate (CVSS 3.1 score 5.5, confidentiality-only), but such kernel info leaks are commonly useful as a reconnaissance or bypass component in a broader exploit chain. All Samsung mobile devices running Android with a security patch level older than SMR MAR-2021 Release 1 are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-11-08), and related reporting indicates a surveillance vendor exploited Samsung phone zero-days, though no public PoC is known.

What to do: Update affected Samsung devices to SMR MAR-2021 Release 1 or any later monthly security update, and verify on each device (Settings > About phone > Software information) that the Android security patch level is March 2021 or newer. Because exploitation is confirmed (CISA KEV) and this flaw requires local access, prioritize patching devices used by high-risk individuals and review which apps have permission to read device logs.

Affected
Samsung Mobile devices (Android)Prior to SMR MAR-2021 Release 1
Estimated exposure
massTens to hundreds of millions of Samsung Android devices were technically affected until patched (Samsung's smartphone install base is in the hundreds of… — Samsung is the largest Android vendor by shipment volume, with hundreds of millions of active smartphones globally, and every device whose security patch level predates the March 2021 release was within the affected range until updated;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news