ZeroHour

CVE-2021-25394

KEVmass

Use-After-Free Race Condition in Samsung Mobile MFC Charger Driver

CISA: Samsung Mobile Devices Race Condition Vulnerability

CVSS 3.1
6.4 medium
EPSS
<1%p34
Published
()
KEV added
AI analysis

CVE-2021-25394 is a use-after-free vulnerability caused by a race condition in the MFC charger driver on Samsung mobile devices, fixed in Samsung's May 2021 security release (SMR MAY-2021 Release 1). The flaw is triggered when the driver frees a memory object while it is still in use during charger-driver processing, and it can only be exploited to gain an arbitrary write if the attacker has already compromised radio (baseband) privileges, making it a second stage in a modem-to-kernel exploit chain. A successful exploit yields an arbitrary write in kernel space, which an attacker can use to escalate privileges and take full control of the device. Any Samsung mobile device running firmware older than the May 2021 security release is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, confirming exploitation in the wild, though EPSS estimates only a 0.4% probability of exploitation in the next 30 days and no public proof-of-concept is known.

What to do: Apply the SMR MAY-2021 Release 1 security update, or a later Samsung monthly security release, to all Samsung mobile devices, in line with CISA's required action to apply updates per vendor instructions. Because exploitation requires a previously compromised radio, keep baseband/modem firmware current as well. Verify the device security patch level is May 2021 or later before treating it as remediated.

Affected
samsung android (Samsung Mobile Devices)device firmware prior to SMR MAY-2021 Release 1
Estimated exposure
masshundreds of millions of devices (Samsung's global Android installed base) — Samsung accounts for roughly a fifth of global smartphone sales with an active installed base in the hundreds of millions, and the affected range covers all device firmware issued before the May 2021 security release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-416, CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news