CVE-2021-25395
KEVmassRace Condition in Samsung Mobile MFC Charger Driver Allows Signature-Check Bypass
CISA: Samsung Mobile Devices Race Condition Vulnerability
CVE-2021-25395 is a race condition (CWE-362) in the MFC charger driver on Samsung mobile devices running Android, present in firmware released prior to the Samsung Mobile Release (SMR) MAY-2021 Release 1 security update. To trigger it, a local attacker must first compromise a radio (modem-level) privilege, then win a timing window in the driver's processing. Successful exploitation lets the attacker bypass a signature check, with the CVSS scoring high confidentiality, integrity, and availability impact once the high-privilege prerequisite is met. Any Samsung mobile device not yet running the May 2021 (or later) Samsung security update is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-06-29, indicating observed exploitation in the wild, even though EPSS currently estimates only a ~0.4% probability of exploitation over the next 30 days.
What to do: Apply the Samsung Mobile Release (SMR) MAY-2021 Release 1 security update or later — ideally the latest available patch — to all Samsung mobile devices, and verify each device's Android security patch level in Settings or via MDM. Because the flaw is on CISA's Known Exploited Vulnerabilities list, prioritize patching devices used by high-risk users; if updates are no longer available for a device, follow CISA's required action and discontinue its use. Remediation of prerequisite conditions (e.g., any compromise of radio/modem privilege) also limits exposure.
| Samsung Mobile Devices (Android; MFC charger driver) | All firmware prior to the Samsung Mobile Release (SMR) MAY-2021 Release 1 security update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
- Affected
- Samsung Mobile Devices
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H