CVE-2021-25372 is an improper boundary check vulnerability in the DSP driver of Samsung Android devices utilizing Exynos 2100, 980, and 9830 chipsets, allowing for out-of-bounds memory access. This vulnerability carries a CVSS score of 6.7 (Medium) and poses a significant risk due to its potential for high impact on confidentiality, integrity, and availability, requiring high privileges for exploitation. Crucially, this CVE is actively exploited in the wild, as indicated by its presence on CISA's KEV catalog and media coverage suggesting exploitation by spyware vendors. Despite active exploitation, no public exploit code is available in Metasploit, Nuclei, or ExploitDB, though it has garnered substantial community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:10.0:smr-feb-2021-r1:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:10.0:smr-jan-2021-r1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:11.0:smr-feb-2021-r1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:samsung:android:11.0:smr-jan-2021-r1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.