ZeroHour

CVE-2023-21492

KEVmass

Kernel Pointer Leak in Logs Enables ASLR Bypass on Samsung Mobile Devices

CISA: Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability

CVSS 3.1
4.4 medium
EPSS
3%p84
Published
()
KEV added
AI analysis

CVE-2023-21492 is an information disclosure flaw in Samsung mobile devices in which kernel pointers are written to the device log file, a classic CWE-532 'sensitive data in logs' issue. Triggering requires local access with high (privileged) privileges; an attacker or app with such access can read the leaked pointers from the log. The disclosed addresses let the attacker defeat ASLR (address space layout randomization), which is typically used as a stepping stone in a local privilege-escalation or kernel-exploitation chain rather than as a standalone compromise. Affected devices are Samsung mobile devices running Android whose security patch level predates the SMR May-2023 Release 1. Exploitation is confirmed in the wild: CISA added the issue to the Known Exploited Vulnerabilities catalog on 2023-05-19, though no public proof-of-concept is known and any ransomware connection is unknown.

What to do: Apply Samsung's SMR May-2023 Release 1 security update or later (check Settings > Software update) and confirm the installed security patch level on managed devices. CISA's KEV entry requires applying vendor updates, so prioritize fleet devices used by high-risk or high-value users. Because exploitation requires local privileged access, there is limited remote exposure, but active in-the-wild exploitation makes prompt patching important.

Affected
Samsung Mobile Devices (Android)All Samsung mobile devices with security patch level prior to SMR May-2023 Release 1
Estimated exposure
masson the order of tens of millions of unpatched devices out of hundreds of millions of Samsung Android devices in use (devices not yet updated to SMR May-2023… — Samsung is one of the world's largest Android smartphone vendors with hundreds of millions of active devices, and the flaw applies to every device whose patch level predates the May-2023 Samsung release; the unpatched share is an estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

CISA Known Exploited Vulnerability
Affected
Samsung Mobile Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
samsung
Products
android
Weakness
CWE-532
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news