Out-of-Bounds Write Vulnerability in Samsung Exynos Mobile and Wearable Processors
CVE-2025-27807

9.1CRITICAL

Key Information:

Vendor

Samsung

Vendor
CVE Published:
5 January 2026

What is CVE-2025-27807?

A vulnerability has been identified in Samsung's Exynos family of processors, specifically affecting various mobile and wearable devices. This flaw results from a lack of length checks, allowing for out-of-bounds writes when processing malformed NAS packets. Such a vulnerability can potentially enable attackers to execute arbitrary code, leading to severe impacts on device integrity and security. It is critical for users to be aware of their device versions and apply patches promptly.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.