CVE-2021-25394
KEVmassUse-After-Free Race Condition in Samsung Mobile MFC Charger Driver
CISA: Samsung Mobile Devices Race Condition Vulnerability
CVE-2021-25394 is a use-after-free vulnerability caused by a race condition in the MFC charger driver on Samsung mobile devices, fixed in Samsung's May 2021 security release (SMR MAY-2021 Release 1). The flaw is triggered when the driver frees a memory object while it is still in use during charger-driver processing, and it can only be exploited to gain an arbitrary write if the attacker has already compromised radio (baseband) privileges, making it a second stage in a modem-to-kernel exploit chain. A successful exploit yields an arbitrary write in kernel space, which an attacker can use to escalate privileges and take full control of the device. Any Samsung mobile device running firmware older than the May 2021 security release is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, confirming exploitation in the wild, though EPSS estimates only a 0.4% probability of exploitation in the next 30 days and no public proof-of-concept is known.
What to do: Apply the SMR MAY-2021 Release 1 security update, or a later Samsung monthly security release, to all Samsung mobile devices, in line with CISA's required action to apply updates per vendor instructions. Because exploitation requires a previously compromised radio, keep baseband/modem firmware current as well. Verify the device security patch level is May 2021 or later before treating it as remediated.
| samsung android (Samsung Mobile Devices) | device firmware prior to SMR MAY-2021 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
- Affected
- Samsung Mobile Devices
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-416, CWE-362
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H