LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-25487: Samsung Mobile Devices Out-of-Bounds Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 29, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 20, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-25487 to its Known Exploited Vulnerabilities catalog on Jun 29, 2023, with a federal patch deadline of Jul 20, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution…

CVE-2021-25487 is an out-of-bounds read vulnerability in the modem interface driver on Samsung mobile devices. It stems from missing boundary checks on a buffer inside set_skb_priv(), which can allow an attacker to trigger remote code execution by causing the system to dereference an invalid function pointer. For IT and security teams managing fleets of Samsung handsets or tablets, this matters because a successful exploit could give an attacker code execution on the device itself, potentially compromising corporate data, credentials, or network access if the device is enrolled in enterprise management.

Public detail is limited to the CISA description and the CWE classification; exact affected builds, attack vectors, and conditions must be confirmed against the vendor advisory before any assessment or response plan is finalized.

How it works

The weakness is classified as CWE-125 (Out-of-bounds Read). In the modem interface driver, the function set_skb_priv() fails to enforce proper boundary checking on a buffer. An attacker who can supply crafted input that reaches this code path can cause the driver to read past the end of the intended buffer. The CISA summary states that this leads to remote code execution through the subsequent dereference of an invalid function pointer. No further exploit mechanics, required privileges, or network versus local delivery details are provided in the available facts, so defenders should treat the issue as a remote-code-execution risk in the modem stack and verify the precise preconditions in Samsung’s advisory.

Am I affected? How to find it in your systems

The vulnerability affects Samsung mobile devices. These devices commonly appear as employee-owned or corporate-issued phones and tablets that may be enrolled in mobile-device management (MDM) platforms, connected to corporate Wi-Fi or VPN, or used for email and collaboration apps.

Because no specific version ranges are supplied in the facts, treat every Samsung mobile device as potentially affected until the advisory confirms otherwise.

How to remediate

The primary remediation is to apply the updates issued by Samsung according to the vendor instructions. CISA’s required action is to apply those updates or to discontinue use of the product if updates are unavailable. Once the vendor patch is installed, verify the new security-patch level or baseband version matches the fixed release.

If you can't patch immediately

When immediate patching is not feasible, apply compensating controls that reduce exposure of the modem interface and limit the impact of a successful exploit.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to device compromise and subsequent data exposure. Known ransomware use of CVE-2021-25487 is not documented in the available facts. If you suspect a device was compromised, isolate it, collect forensic artifacts, and rotate any credentials or tokens that may have been accessible from the device. You can also run a free exposure scan of your email addresses to check whether those addresses appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSamsung · Mobile Devices
WeaknessCWE-125
Added to CISA KEVJun 29, 2023
Federal patch deadlineJul 20, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities