Out-of-bounds Write in SecFR Trustlet Affects Samsung Mobile Devices
CVE-2025-20943
6.4MEDIUM
Summary
The out-of-bounds write vulnerability present in the SecFR trustlet prior to the April 2025 SMR Release 1 can be exploited by local privileged attackers, potentially leading to unauthorized memory modifications. This vulnerability raises significant concerns regarding the integrity of device memory and the overall security posture of affected Samsung mobile devices.
Affected Version(s)
Samsung Mobile Devices SMR Apr-2025 Release in Android 13, 14, 15
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved