Samsung Mobile Devices Use-After-Free Vulnerability (CVE-2022-22265)
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
A local attacker, with a low-privilege account, can achieve full data confidentiality loss, partial data tampering, partial service disruption. Federal agencies are required to remediate by 2023-10-09 under CISA BOD 22-01.
This is a Software Vulnerability (CWE-703) (CWE-703) vulnerability in Samsung Mobile Devices. An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. Exploitation requires local access, higher attack complexity, a low-privilege authenticated account, and user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-09-18 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2023-10-09.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.