ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Surveillance vendor exploited Samsung phone zero-days

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-25337CVE-2021-25369CVE-2021-25370

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-25337
Improper Access Control in Samsung Mobile Clipboard Service Lets Apps Read/Write Local Files

CVE-2021-25337 is an improper access control flaw (CWE-269) in the clipboard service of Samsung mobile devices, present in devices running security patch levels prior to Samsung's March 2021 Security Maintenance Release (SMR Mar-2021 Release 1). An untrusted application installed on the device can abuse the flaw to read or write certain local files that it should not be able to access, meaning a malicious or compromised app gains unauthorized access to sensitive data or can tamper with files on the device. The attack is local (AV:L) and requires user interaction, so exploitation requires a hostile app already running on the handset rather than a remote or network-based attack. All Samsung mobile devices on patch levels older than the March 2021 SMR are affected until they are updated. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-11-08, and related reporting indicates a surveillance vendor exploited Samsung phone zero-days, though no public proof-of-concept is known and ransomware use is unknown.

Do: Update affected Samsung devices to SMR Mar-2021 Release 1 or a later monthly security maintenance release via the vendor's update mechanism (Settings > Software update), per CISA's required action to apply vendor updates. For fleets, check device security patch levels via MDM or the device's security patch version in Settings and confirm it is March 2021 or newer; treat any untrusted sideloaded apps on unpatched devices as potential local file-access risk.

7.13% KEV
  • Samsung Mobile Devices (Android) All Samsung mobile devices prior to SMR Mar-2021 Release 1 (security patch level earlier than March 2021)
masshundreds of millions of devices potentially affected (all Samsung phones/tablets not yet on the March 2021 SMR or later)
CVE-2021-25369
+1 in the same advisory: …25370
Improper Access Control in Samsung Mobile sec_log Exposes Kernel Information

CVE-2021-25369 is an improper access control flaw (CWE-200) in the sec_log file on Samsung mobile devices, which exposes sensitive kernel information to userspace on devices prior to the March 2021 Samsung security release (SMR MAR-2021 Release 1). It is triggered locally: a low-privileged user or app on the device can read the insufficiently protected sec_log file (local attack vector, no user interaction required). An attacker gains disclosure of sensitive kernel information; the standalone impact is moderate (CVSS 3.1 score 5.5, confidentiality-only), but such kernel info leaks are commonly useful as a reconnaissance or bypass component in a broader exploit chain. All Samsung mobile devices running Android with a security patch level older than SMR MAR-2021 Release 1 are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-11-08), and related reporting indicates a surveillance vendor exploited Samsung phone zero-days, though no public PoC is known.

Do: Update affected Samsung devices to SMR MAR-2021 Release 1 or any later monthly security update, and verify on each device (Settings > About phone > Software information) that the Android security patch level is March 2021 or newer. Because exploitation is confirmed (CISA KEV) and this flaw requires local access, prioritize patching devices used by high-risk individuals and review which apps have permission to read device logs.

5.5
group max
1% KEV
  • Samsung Mobile devices (Android) Prior to SMR MAR-2021 Release 1
massTens to hundreds of millions of Samsung Android devices were technically affected until patched (Samsung's smartphone install base is in the hundreds of…
Full article540 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 09, 2022

Google Project Zero researchers reported that a surveillance vendor is using three Samsung phone zero-day exploits.

Google Project Zero disclosed three Samsung phone vulnerabilities, tracked as CVE-2021-25337, CVE-2021-25369 and CVE-2021-25370, that have been exploited by a surveillance company.

The three issues are:

  • CVE-2021-25337: Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
  • CVE-2021-25369: An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
  • CVE-2021-25370: An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

The researchers pointed out that the surveillance firm included in its spyware the exploits for these three vulnerabilities that were zero-day at the time of their exploitation.

“This in-the-wild exploit chain is a great example of different attack surfaces and “shape” than many of the Android exploits we’ve seen in the past. All three vulnerabilities in this chain were in the manufacturer’s custom components rather than in the AOSP platform or the Linux kernel.” reads the advisory published by Google Project Zero. “It’s also interesting to note that 2 out of the 3 vulnerabilities were logic and design vulnerabilities rather than memory safety.”

The surveillance vendor chained the above vulnerabilities to compromise the Samsung phones.

The TAG team only obtained a partial exploit chain for Samsung phones that were likely in the testing phase. The experts revealed that the sample is dated back late 2020.

“The chain merited further analysis because it is a 3 vulnerability chain where all 3 vulnerabilities are within Samsung custom components, including a vulnerability in a Java component.” reported the advisory.

The experts explained that the exploit sample targets Samsung phones running kernel 4.14.113 with the Exynos SOC. This specific SOCs is used by phones sold in the Europe and Africa. The exploit relies on both the Mali GPU driver and the DPU driver which are specific to the Exynos Samsung phones.

Samsung phones that were running kernel 4.14.113 in late 2020 include the S10, A50, and A51.

Google reported the vulnerabilities to Samsung immediately after their discovery in late 2020s, and the vendor addressed them in March 2021.

Google did not reveal the name of the surveillance vendor, it only highlighted similarities with other campaigns that targeted Android users is Italy and Kazakhstan.

Project Zero noted that the advisories published by Samsung for these issues do not mention their exploitation in-the-wild.

“Labeling when vulnerabilities are known to be exploited in-the-wild is important both for targeted users and for the security industry. When in-the-wild 0-days are not transparently disclosed, we are not able to use that information to further protect users, using patch analysis and variant analysis, to gain an understanding of what attackers already know.” concludes the report.

“The analysis of this exploit chain has provided us with new and important insights into how attackers are targeting Android devices. It highlights a need for more research into manufacturer specific components.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/138302/hacking/surveillance-vendor-exploited-samsung-phone-zero-days.html