First published: Wed May 07 2025(Updated: )
Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Keymaster Trustlet | <SMR May-2025 Release 1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2025-20937 vulnerability is considered high severity due to its potential for local privileged attackers to execute out-of-bounds memory writes.
To fix CVE-2025-20937, update the Keymaster trustlet to the version released in SMR May-2025 Release 1 or later.
CVE-2025-20937 affects the Keymaster trustlet versions prior to SMR May-2025 Release 1.
CVE-2025-20937 can be exploited by local privileged attackers who have access to the affected system.
The risks associated with CVE-2025-20937 include the potential for unauthorized memory access and manipulation, leading to data corruption or system compromise.