LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-25369: Samsung Mobile Devices Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-25369 to its Known Exploited Vulnerabilities catalog on Nov 8, 2022, with a federal patch deadline of Nov 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This…

CVE-2021-25369 is an improper access control vulnerability in Samsung mobile devices that use the Mali GPU. It centers on the sec_log file and allows sensitive kernel information to become readable from userspace.

This matters to IT and security teams because the leaked kernel details can serve as a building block for further compromise. The flaw has been chained with CVE-2021-25337 and CVE-2021-25370, increasing the risk that a local foothold could escalate into broader device control. Ransomware use is not documented, yet any exposure of kernel state on managed mobile fleets warrants prompt attention.

How it works

The weakness is catalogued as CWE-200, exposure of sensitive information. On affected Samsung devices equipped with a Mali GPU, access controls around the sec_log file are insufficient. As a result, processes running in userspace can obtain kernel-level details that should remain restricted.

An attacker who already has code execution on the device—whether through a malicious app, another vulnerability, or physical access—can read the improperly protected sec_log content. The harvested kernel information supplies the reconnaissance needed to refine subsequent exploits. Public detail does not describe the precise read primitives or memory layouts involved; those mechanics must be confirmed against the vendor advisory. The documented chaining with two companion CVEs shows how the information leak can be combined with other flaws to achieve higher impact.

Am I affected? How to find it in your systems

The vulnerability applies to Samsung mobile devices that incorporate a Mali GPU. Typical environments include corporate-issued smartphones and tablets, BYOD devices enrolled in mobile-device management (MDM), and any Samsung handset used to access enterprise resources.

How to remediate

The primary remediation is to apply the updates issued by Samsung, following the vendor’s instructions as directed by CISA. Confirm the precise patch packages, build numbers, and deployment steps in the official advisory before rolling them out.

If you can't patch immediately

When immediate patching is blocked by operational constraints, apply compensating controls that reduce the attack surface until the official update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure. Although ransomware use is not documented for this CVE, treat any confirmed exploitation as a potential breach event. Review device logs, revoke credentials stored on the device, and force re-authentication for enterprise services. Readers can also run a free exposure scan of their email address to check whether associated accounts appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSamsung · Mobile Devices
WeaknessCWE-200
Added to CISA KEVNov 8, 2022
Federal patch deadlineNov 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities