Samsung Exynos Processors Out-of-Bounds Write Vulnerability via Malformed USB Packets

Vulnerability

A high-severity out-of-bounds write vulnerability has been identified in various Samsung mobile and wearable processors, including Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, and W1000. The vulnerability arises from a lack of proper length validation, allowing for out-of-bounds writes when the processor receives malformed USB packets.

Impact

Exploitation of this vulnerability leads to out-of-bounds writes, which can commonly result in memory corruption or arbitrary code execution.

Added: Nov 4, 2025, 9:17 PM
Updated: Nov 4, 2025, 10:20 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.