MEDIUM

CVE-2021-25395

Samsung Android 2021-06-11 CVSS v3.1
CVSS
6.4
KEV

Description

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

Summary dbcve.org

A race condition vulnerability in Samsung's MFC (Magnetic Fast Charging) charger driver allows local attackers with compromised radio privileges to bypass signature verification checks. This authorization bypass occurs due to timing issues in the driver code prior to the SMR MAY-2021 security update, potentially enabling privilege escalation or malicious driver interaction.

Mitigation

Apply the SMR MAY-2021 Release 1 or later security patch to affected Samsung devices. Organizations should ensure mobile device management (MDM) policies enforce timely security updates, particularly for devices with access to sensitive radio/communication subsystems.

Weakness (CWE)

CWE-362 Race Condition

EPSS Score

0.37%
Probability of exploitation in next 30 days
27.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE