Samsung Mobile Out-of-Bounds Write Vulnerability in libsthmbc.so Allowing Arbitrary Code Execution
Vulnerability
A high-severity out-of-bounds write vulnerability has been identified in the libsthmbc.so library, affecting Samsung Mobile devices running Android 12, 13, and 14, prior to the January 2025 Security Maintenance Release. This vulnerability allows local attackers to execute arbitrary code with elevated privileges, requiring user interaction to trigger. The issue arises from improper handling of block sizes for smp4vtd, leading to memory corruption that can be exploited for code execution.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code with elevated privileges on the affected device.
Remediation
Users can apply the January 2025 Security Maintenance Release to address this vulnerability. This update is part of the regular monthly security update process and includes patches from both Google and Samsung.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
