Android
cpe:2.3:o:samsung:android:*:*:*:*:*:*:*
- 12
- 13
- 14
A vulnerability exists in Samsung Mobile devices running Android 12, 13, or 14, prior to the January 2025 Security Maintenance Release. The issue is an out-of-bounds write in the library libsthmbc.so, specifically in the frame buffer decoding process. This vulnerability allows local attackers to execute arbitrary code with elevated privileges, but requires user interaction to trigger.
Exploitation of this vulnerability could lead to arbitrary code execution with elevated privileges on the affected device.
Users can update to the January 2025 Security Maintenance Release to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.