Samsung Exynos Fastboot USB Interface
cpe:2.3:o:samsung:exynos_firmware:*:*:*:*:*:*:*
- < SMR Apr-2023 Release 1
A vulnerability exists in the Exynos Fastboot USB interface on select Android 11, 12, and 13 devices, prior to the April 2023 Security Maintenance Release. This vulnerability allows a physical attacker to execute arbitrary code in the bootloader due to improper input validation. The issue was privately disclosed and is part of the Samsung Vulnerabilities and Exposures (SVE) program.
Exploitation of this vulnerability allows for arbitrary code execution in the bootloader, which could potentially be used to compromise the device at a low level, such as unlocking the bootloader or modifying the operating system.
Users can apply the April 2023 Security Maintenance Release, which includes the necessary patch for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.