First published: Thu Sep 09 2021(Updated: )
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25455 is considered a high severity vulnerability due to the potential for arbitrary memory access.
To fix CVE-2021-25455, update your Android device to the latest software version that includes the security patch released in September 2021.
CVE-2021-25455 is an out-of-bounds read vulnerability affecting the libsaviextractor.so library.
CVE-2021-25455 affects Google Android versions 8.1, 9.0, 10.0, and 11.0.
Yes, CVE-2021-25455 can be exploited remotely through a specially crafted AVI file.