EXPOSURES › CVE-2021-25369
CVE-2021-25369
HIGH ⌖ ON CISA KEV · EXPLOITEDSamsung mobile devices exposed kernel info due to improper access control
Samsung's Mali GPU-based mobile devices had an unpatched improper access control vulnerability in the sec_log file, allowing sensitive kernel information to be exposed to userspace. This was exploited in the wild, affecting multiple devices.
Shame score — Critical vulnerability actively exploited in the field with no indication of patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.