CVE-2021-25337: Samsung Mobile Devices Improper Access Control Vulnerability
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
Other sources
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung mobile devices (Android clipboard service)to a version that resolves this vulnerability.Patch SMR Mar-2021 Release 1
Event History
Frequently Asked Questions
What is CVE-2021-25337?
CVE-2021-25337 is an improper access control vulnerability in Samsung mobile devices' clipboard service that allows untrusted applications to read or write arbitrary files.
How does CVE-2021-25337 impact Samsung mobile devices?
CVE-2021-25337 allows untrusted applications to access and modify files on Samsung mobile devices through the clipboard service.
What other vulnerabilities are CVE-2021-25337 chained with?
CVE-2021-25337 was chained with CVE-2021-25369 and CVE-2021-25370.
How can I mitigate CVE-2021-25337 on my Samsung mobile device?
Apply the security update provided by Samsung to fix CVE-2021-25337.
Where can I find more information about CVE-2021-25337?
You can find more information about CVE-2021-25337 on the Samsung Mobile Security website.