CVE-2022-22265
KEVmassUse-After-Free in Samsung Mobile NPU Driver Allows Local Code Execution
CISA: Samsung Mobile Devices Use-After-Free Vulnerability
CVE-2022-22265 is a use-after-free flaw — an improper check or handling of exceptional conditions (CWE-703) — in the neural processing unit (NPU) driver on Samsung mobile devices. A local attacker with limited privileges, such as a malicious app already on the handset, can trigger the flaw without user interaction, causing an arbitrary memory write and arbitrary code execution, effectively a full local privilege escalation. All Samsung mobile devices running a Samsung Mobile Security Release older than the January 2022 (SMR Jan-2022 Release 1) patch level are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-18, confirming exploitation in the wild, although CISA lists ransomware use as unknown and EPSS assigns a modest 0.4% probability of exploitation in the next 30 days.
What to do: Apply the January 2022 Samsung Mobile Security Release (SMR Jan-2022 Release 1) or any later monthly Samsung security update to all Samsung mobile devices, and verify patch levels via Settings > Software update, prioritizing KEV-listed, unpatched fleets. Because the flaw requires local access, avoid installing untrusted apps on devices pending the update. CISA's required action is to apply vendor mitigations or discontinue use if updates are unavailable.
| Samsung Mobile Devices (Android) — NPU driver | all devices/patch levels prior to SMR Jan-2022 Release 1 |
| Google Android (CPE platform encoding for the affected Samsung devices) | as running on Samsung devices without the January 2022 Samsung security update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
- Affected
- Samsung Mobile Devices
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- android
- Weakness
- CWE-703
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H