CVE-2025-27807: Critical severity Samsung Exynos vulnerability
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes via malformed NAS packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27807?
The CVE-2025-27807 vulnerability is considered to be of high severity due to its potential to allow unauthorized access and out-of-bounds writes.
How do I fix CVE-2025-27807?
To fix CVE-2025-27807, it is recommended to install the latest firmware updates provided by Samsung for affected Exynos processors.
Which devices are affected by CVE-2025-27807?
CVE-2025-27807 affects a range of Samsung devices utilizing Exynos processors such as the 980, 990, 850, 1080, and several modem models.
What is the nature of the vulnerability in CVE-2025-27807?
CVE-2025-27807 is caused by a lack of length check leading to potential out-of-bounds writes in malformed NAS packets.
Is there a workaround for CVE-2025-27807?
Currently, the best approach for CVE-2025-27807 is to apply the security updates provided by Samsung, as no alternative workaround has been officially provided.