Samsung Exynos Processors Out-of-Bounds Write Vulnerability in NRMM

Vulnerability

A vulnerability exists in the NRMM component of various Samsung mobile and wearable processors, as well as certain Exynos modem chipsets. The issue arises from a lack of proper boundary checks when decoding Registration Accept messages, which can result in out-of-bounds write operations on the stack. Affected processors include the Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, and W1000, along with Modem 5123, Modem 5300, and Modem 5400.

Impact

Exploitation of this vulnerability can lead to stack-based buffer overflows, potentially allowing for arbitrary code execution or causing a denial-of-service condition.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.