Out-of-Bounds Access in Samsung Exynos Mobile and Wearable Processors
CVE-2024-50600
7.5HIGH
Key Information:
- Vendor
- Samsung
- Vendor
- CVE Published:
- 6 March 2025
Summary
A vulnerability has been identified in Samsung's Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, and W920, W930, W1000 processors that allows for out-of-bounds access. This issue arises from a lack of boundary check in the STOP_KEEP_ALIVE_OFFLOAD function, permitting attackers to exploit the vulnerability by sending specially crafted messages through the Wi-Fi driver. This could potentially lead to unauthorized access or manipulation of sensitive data within devices utilizing these processors, raising significant security concerns.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved