Samsung Mobile Secfr Trustlet Out-of-Bounds Write Vulnerability Allowing Memory Corruption

Vulnerability

A high-severity out-of-bounds write vulnerability has been identified in the secfr trustlet of Samsung Mobile devices, prior to the SMR April 2025 Release 1. This vulnerability allows local privileged attackers to cause memory corruption. The issue arises from improper input validation, which can be exploited to write data outside the intended boundaries, potentially leading to arbitrary code execution or other malicious outcomes.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or other malicious outcomes by allowing attackers to manipulate memory in unintended ways.

Remediation

Users can apply the SMR April 2025 Release 1 update to address this vulnerability. This update is part of the monthly Security Maintenance Release process and includes patches from both Google and Samsung. For detailed information on Samsung's security update process, please refer to the Samsung Mobile Security Update page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.