CVE-2025-21007: Medium severity Android libsavsvc vulnerability
Published Jul 8, 2025
·Updated
Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
Affected Software
2 affected components
Android libsavsvc<15
Samsung android<15.0
Event History
Jul 8, 2025
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21007?
CVE-2025-21007 is classified as a high-severity vulnerability due to its potential to cause memory corruption.
2
How do I fix CVE-2025-21007?
To fix CVE-2025-21007, upgrade libsavsvc to version 15 or later on affected Android devices.
3
Who is affected by CVE-2025-21007?
CVE-2025-21007 impacts users of Android devices running libsavsvc versions prior to 15.
4
Can CVE-2025-21007 be exploited remotely?
CVE-2025-21007 requires local access to exploit, making remote exploitation unlikely.
5
What are the risks of CVE-2025-21007?
Exploitation of CVE-2025-21007 can lead to arbitrary memory access and potentially unauthorized code execution.