ZeroHour

CVE-2021-25395

KEVmass

Race Condition in Samsung Mobile MFC Charger Driver Allows Signature-Check Bypass

CISA: Samsung Mobile Devices Race Condition Vulnerability

CVSS 3.1
6.4 medium
EPSS
<1%p30
Published
()
KEV added
AI analysis

CVE-2021-25395 is a race condition (CWE-362) in the MFC charger driver on Samsung mobile devices running Android, present in firmware released prior to the Samsung Mobile Release (SMR) MAY-2021 Release 1 security update. To trigger it, a local attacker must first compromise a radio (modem-level) privilege, then win a timing window in the driver's processing. Successful exploitation lets the attacker bypass a signature check, with the CVSS scoring high confidentiality, integrity, and availability impact once the high-privilege prerequisite is met. Any Samsung mobile device not yet running the May 2021 (or later) Samsung security update is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, indicating observed exploitation in the wild, even though EPSS currently estimates only a ~0.4% probability of exploitation over the next 30 days.

What to do: Apply the Samsung Mobile Release (SMR) MAY-2021 Release 1 security update or later — ideally the latest available patch — to all Samsung mobile devices, and verify each device's Android security patch level in Settings or via MDM. Because the flaw is on CISA's Known Exploited Vulnerabilities list, prioritize patching devices used by high-risk users; if updates are no longer available for a device, follow CISA's required action and discontinue its use. Remediation of prerequisite conditions (e.g., any compromise of radio/modem privilege) also limits exposure.

Affected
Samsung Mobile Devices (Android; MFC charger driver)All firmware prior to the Samsung Mobile Release (SMR) MAY-2021 Release 1 security update
Estimated exposure
masshundreds of millions of Samsung Galaxy devices shipped (roughly 20% of global Android market share); the currently vulnerable subset is devices still below the… — Samsung is the largest Android OEM, with annual smartphone shipments in the hundreds of millions and a cumulative installed base in the hundreds of millions to billions, so potential exposure is mass-scale, shrinking over time as devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news