Samsung Mobile Out-of-Bounds Write Vulnerability in SoftSIM Trustlet Allowing Memory Corruption

Vulnerability

A high-severity out-of-bounds write vulnerability has been identified in the SoftSIM trustlet, affecting select devices running Android 12, 13, and 14, prior to the January 2025 Security Maintenance Release. This vulnerability allows local privileged attackers to cause memory corruption. The issue arises from improper input validation, which can be exploited by attackers with elevated privileges.

Impact

Exploitation of this vulnerability leads to memory corruption, which could potentially be leveraged to execute arbitrary code with privileges.

Remediation

Users can apply the January 2025 Security Maintenance Release to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
2.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.