Vulnerability details
Advisory: SB2023052602 - Multiple vulnerabilities in Samsung Mobile Firmware
Vulnerable component: Samsung Mobile Firmware
CVE-ID: CVE-2023-21492
CVSSv3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:H/RL:O/RC:C
CWE-ID: CWE-532 - Information Exposure Through Log Files
Description:
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to kernel pointers are printed into the log file. A local application can read the log file and use the kernel pointers to bypass ASLR protection.
Note, the vulnerability is being exploited in the wild.
External links:
https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=05