Out-of-bounds Write Vulnerability in Samsung Mobile's libsthmbc.so
CVE-2025-20882

7HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 February 2025

Summary

The vulnerability exists due to an out-of-bounds write condition that exposes uninitialized memory in libsthmbc.so prior to the SMR Jan-2025 Release 1. Local attackers can exploit this flaw to execute arbitrary code, but it requires user interaction to trigger the vulnerability. This can lead to significant security risks if exploited, highlighting the importance of keeping software up-to-date.

Affected Version(s)

Samsung Mobile Devices SMR Jan-2025 Release in Android 12, 13, 14

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.