Skip to content
COOEY

FAIL › dossier

Mobile Devices

PRODUCT

· dossier confidence 50%

Samsung's mobile devices have a history of significant security vulnerabilities, indicating a need for improved secure development practices and rigorous testing. These vulnerabilities pose a risk to data confidentiality and system integrity, requiring careful mitigation and ongoing monitoring.

PROFILE
CategoryConsumer ElectronicsWhat they doSamsung manufactures mobile devices, including smartphones and tablets, and a range of other consumer electronics.
SECURITY POSTURE

Samsung's mobile devices have demonstrated a recurring pattern of high-severity vulnerabilities, including remote code execution and memory corruption issues. These vulnerabilities frequently stem from improper input validation, race conditions, and access control failures within critical drivers and components.

Notable failures
  • Remote code execution via libimagecodec.quram.so
  • Use-after-free vulnerability in Exynos chipsets
  • Out-of-bounds read in modem interface driver
  • Improper boundary check in DSP driver
  • Race condition in MFC charger driver
  • Sensitive information insertion into log files
  • Memory corruption in Mali GPU driver
  • Improper access control in sec_log file
  • Clipboard service vulnerability allowing arbitrary file access
Patterns: Recurring RCE vulnerabilities; Improper input validation; Race conditions in drivers; Access control failures; Memory corruption vulnerabilities
FAILURE HISTORY · 13
DATEEVENTSEVSUMMARY
2025-11-10 CVE-2025-21042 high Samsung mobile devices had an unpatched out-of-bounds write vulnerability allowing remote code execution.
2025-10-02 CVE-2025-21043 high Samsung mobile devices vulnerable to remote code execution due to an out-of-bounds write in libimagecodec.quram.so
2023-09-18 CVE-2022-22265 high Samsung Exynos chipsets allow malicious memory write and code execution.
2023-06-29 CVE-2021-25371 high Samsung mobile devices have an unspecified vulnerability allowing arbitrary code execution via ELF library loading within the DSP driver, and it's currently being exploited in the wild.
2023-06-29 CVE-2021-25372 high Samsung mobile devices had an improperly checked boundary in their DSP driver, leading to out-of-bounds memory access and active exploitation in the wild.
2023-06-29 CVE-2021-25487 high Samsung mobile devices contained an out-of-bounds read vulnerability allowing remote code execution, and it's currently being exploited in the wild.
2023-05-19 CVE-2023-21492 high Samsung Android devices exposed sensitive info in logs, allowing ASLR bypass.
2022-11-08 CVE-2021-25337 high Samsung mobile devices had unpatched clipboard service access control vulnerability allowing untrusted apps to read or write files
2022-11-08 CVE-2021-25370 high Samsung mobile devices suffer memory corruption Vulnerability
2022-11-08 CVE-2021-25369 high Samsung mobile devices exposed kernel info due to improper access control
2023-06-29 CVE-2021-25489 high Samsung mobile devices had a format string bug in the modem interface driver, leading to kernel panics and active exploitation in the wild.
2023-06-29 CVE-2021-25395 high Samsung mobile devices have a race condition vulnerability allowing unauthorized writes after radio privilege compromise, and it's actively being exploited in the wild.
2023-06-29 CVE-2021-25394 high Samsung mobile devices have a race condition vulnerability allowing unauthorized writes with radio privilege compromise, and it's actively being exploited in the wild.
Open questions: What specific remediation steps are being taken to address the identified vulnerabilities? · What is the extent of third-party component risk management? · How are security awareness and training programs being implemented and evaluated?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:24:29.159121+00:00