EXPOSURES › CVE-2023-21492
CVE-2023-21492
HIGH ⌖ ON CISA KEV · EXPLOITEDSamsung Android devices exposed sensitive info in logs, allowing ASLR bypass.
Samsung mobile devices running Android 11, 12, and 13 have a vulnerability that allows a privileged, local attacker to bypass Address Space Layout Randomization (ASLR), exposing sensitive information in log files. This can lead to unauthorized access and data exposure. DIB organizations should ensure their Android devices are updated to mitigate this risk.
Shame score — The vulnerability allowed an attacker to bypass ASLR, exposing sensitive information, which is a significant security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.