Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability (CVE-2023-21492)
Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.
A local attacker, with administrative privileges, can achieve full data confidentiality loss. Federal agencies are required to remediate by 2023-06-09 under CISA BOD 22-01.
This is a Software Vulnerability (CWE-532) (CWE-532) vulnerability in Samsung Mobile Devices. Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. Exploitation requires local access, low attack complexity, an administrative account, and no user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-05-19 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2023-06-09.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.