First published: Fri Jun 11 2021(Updated: )
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25385 is classified with a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2021-25385, update your affected Android device to the latest available security patch provided by Google.
CVE-2021-25385 affects Google Android versions 8.1, 9.0, 10.0, and 11.0.
CVE-2021-25385 can be exploited by attackers through improper input validation in the mediaextractor process.
CVE-2021-25385 can be exploited remotely by sending crafted malicious media files to the affected systems.