ZeroHour

CVE-2022-22265

KEVmass

Use-After-Free in Samsung Mobile NPU Driver Allows Local Code Execution

CISA: Samsung Mobile Devices Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p33
Published
()
KEV added
AI analysis

CVE-2022-22265 is a use-after-free flaw — an improper check or handling of exceptional conditions (CWE-703) — in the neural processing unit (NPU) driver on Samsung mobile devices. A local attacker with limited privileges, such as a malicious app already on the handset, can trigger the flaw without user interaction, causing an arbitrary memory write and arbitrary code execution, effectively a full local privilege escalation. All Samsung mobile devices running a Samsung Mobile Security Release older than the January 2022 (SMR Jan-2022 Release 1) patch level are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-18, confirming exploitation in the wild, although CISA lists ransomware use as unknown and EPSS assigns a modest 0.4% probability of exploitation in the next 30 days.

What to do: Apply the January 2022 Samsung Mobile Security Release (SMR Jan-2022 Release 1) or any later monthly Samsung security update to all Samsung mobile devices, and verify patch levels via Settings > Software update, prioritizing KEV-listed, unpatched fleets. Because the flaw requires local access, avoid installing untrusted apps on devices pending the update. CISA's required action is to apply vendor mitigations or discontinue use if updates are unavailable.

Affected
Samsung Mobile Devices (Android) — NPU driverall devices/patch levels prior to SMR Jan-2022 Release 1
Google Android (CPE platform encoding for the affected Samsung devices)as running on Samsung devices without the January 2022 Samsung security update
Estimated exposure
masstens to hundreds of millions of Samsung Android devices in the affected install base; exact unpatched subset unknown — Samsung ships on the order of 200+ million smartphones annually and holds roughly a fifth of global smartphone market share, so the cumulative install base far exceeds 1 million devices even though the number still below the January 2022…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
google
Products
android
Weakness
CWE-703
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news