Improper Input Validation in Exynos Fastboot USB Interface by Samsung
CVE-2023-21473

6.8MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
3 September 2025

What is CVE-2023-21473?

The Exynos Fastboot USB Interface by Samsung contains an improper input validation flaw prior to the April 2023 security release, which could allow a physical attacker to execute arbitrary code at the bootloader level. This vulnerability highlights potential security risks associated with the Exynos chipset and emphasizes the importance of timely updates to mitigate exploitation risks.

Affected Version(s)

Samsung Mobile Devices SMR Apr-2023 Release in Selected Android 11, 12, 13 Exynos devices

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.