CVE-2021-25346: Samsung Galaxy S20 libimagecodec Out-Of-Bounds Read Information Disclosure Vulnerability
A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Samsung Galaxy S20. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Quram ImageCodec component. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25346?
CVE-2021-25346 has a high severity due to the potential for arbitrary code execution and sensitive information disclosure.
How do I fix CVE-2021-25346?
To fix CVE-2021-25346, users should update their devices to the latest software version provided by Samsung.
What devices are affected by CVE-2021-25346?
CVE-2021-25346 affects Samsung Galaxy S20 devices running Google Android versions 8.0, 8.1, 9.0, and 10.0.
Can CVE-2021-25346 be exploited remotely?
Yes, CVE-2021-25346 can be exploited remotely, allowing attackers to execute arbitrary code.
What impact does CVE-2021-25346 have on user data?
CVE-2021-25346 can potentially allow attackers to disclose sensitive user information on affected devices.