Heap Overflow Vulnerability in Samsung Bootloader Affects Devices
CVE-2023-42561

6.8MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 December 2023

Summary

A heap out-of-bounds write vulnerability exists in the Samsung bootloader that permits a physical attacker to execute arbitrary code. This flaw impacts devices running versions of the bootloader before SMR Dec-2023 Release 1. Attackers exploiting this vulnerability can gain unauthorized control and potentially compromise sensitive data and system integrity.

Affected Version(s)

Samsung Mobile Devices SMR Dec-2023 Release in Selected Android 11, 12, 13, 14 Qualcomm devices

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.