LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-25371: Samsung Mobile Devices Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 29, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 20, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-25371 to its Known Exploited Vulnerabilities catalog on Jun 29, 2023, with a federal patch deadline of Jul 20, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.

CVE-2021-25371 is an unspecified vulnerability in the DSP driver on Samsung mobile devices. It allows attackers to load ELF libraries inside the DSP. This matters because the DSP is a privileged component that handles media and signal processing; abuse can give an attacker a foothold on the device for further compromise of user data or device integrity. Confirm all product and version details against the vendor advisory.

CISA lists the required action as applying updates per vendor instructions or discontinuing use of the product if updates are unavailable. Known ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-912 (Hidden Functionality). In this case the CISA summary states that the vulnerability resides within the DSP driver and permits attackers to load ELF libraries inside the DSP. On mobile platforms the DSP typically runs with elevated privileges separate from the main application processor. Loading arbitrary ELF libraries into that environment can let an attacker execute code outside normal application sandboxing and security checks.

Exact exploit mechanics, required privileges, and attack vectors are not detailed in the public summary. Defenders should treat this as a local or remote code-execution style issue in a privileged driver and verify the precise conditions in Samsung’s advisory. Do not assume network reachability or user interaction requirements without confirmation from the vendor.

Am I affected? How to find it in your systems

This issue affects Samsung mobile devices that include the vulnerable DSP driver. Such devices are commonly issued as corporate phones, BYOD endpoints, or test/development handsets. Inventory every Samsung device under management—phones, tablets, and any other Samsung mobile hardware that runs the vendor’s Android-based OS.

If the device is no longer supported by Samsung, treat it as unpatchable and plan for replacement.

How to remediate

Patch first. Apply the security update provided by Samsung that addresses CVE-2021-25371, following the vendor’s instructions exactly. CISA’s required action is to apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

As general hardening for this class of driver issues, keep devices on supported OS versions, restrict sideloading of untrusted apps, and enforce strong device encryption and screen-lock policies so that any residual local access is harder to abuse.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as the primary remediation.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure. If you suspect devices were targeted before patching, treat them as potentially compromised: isolate them, collect forensic images where feasible, and rotate credentials that may have been stored or used on the device. Review access logs for anomalous activity originating from those handsets. As a quick additional check, you can run a free exposure scan of your email addresses to see whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSamsung · Mobile Devices
WeaknessCWE-912
Added to CISA KEVJun 29, 2023
Federal patch deadlineJul 20, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities