← Vulnerability feed

Vulnerability record · CVE-2021-25337 · published 4 March 2021

CVE-2021-25337: Samsung clipboard service access control flaw exposes local files

Samsung · Android

Samsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or write certain local files. The flaw is rated high severity (CVSS 7.1) and was added to CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

7.1 CVSS 3.1 High CISA KEV since 8 Nov 2022 EPSS 2.8% · top 14.0% CWE-269 · Improper privilege management
7.1CVSS 3.1 base score, v2 5.8
2.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityHigh CVSS severity plus confirmed inclusion in CISA KEV indicates real-world exploitation, though the local vector and required user interaction limit mass exploitation.

What it is

Samsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or write certain local files. The flaw is rated high severity (CVSS 7.1) and was added to CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.

Impact

An attacker-controlled app can read or write files it should not reach, giving access to potentially sensitive local data and the ability to tamper with files. The CVSS vector shows high confidentiality and integrity impact with no availability impact.

Attack surface

The vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the user must install or launch a malicious app on the device. No network or remote vector is described.

Exploitation

The record is listed in CISA KEV with a due date of 2022-11-29, indicating known exploitation in the wild. EPSS is low at roughly 2.8 percent for the next 30 days, and no ransomware use is documented.

What to do

  • Apply the Samsung SMR Mar-2021 Release 1 or later security update to affected devices.
  • Enforce a policy requiring current Samsung security patch levels on managed mobile devices.
  • Restrict installation of apps to trusted sources and review app permissions on clipboard access.
  • Monitor vendor advisories for any follow-up fixes or revised patch guidance.

Detection

  • Audit managed devices for security patch level below SMR Mar-2021 Release 1.
  • Review app inventories for untrusted or sideloaded applications with clipboard or file access permissions.
  • Monitor for anomalous file read or write activity by non-system apps on affected devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-25337 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Samsung Mobile Devices Improper Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 November 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25337 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-21042Samsung Android libimagecodec.quram.so out-of-bounds writeAn out-of-bounds write in Samsung's libimagecodec.quram.so image codec library, fixed in the SMR Apr-2025 Release 1, allows remote attackers to execu…KEVEPSS 33%analysed9.8CVE-2025-21043Samsung Android libimagecodec Out-of-Bounds Write RCEAn out-of-bounds write in libimagecodec.quram.so, a Samsung image codec library on Android, allows remote code execution. The flaw is reachable witho…KEVEPSS 2.1%analysed7.8CVE-2021-25487Samsung Android modem driver buffer bounds flaw enables code executionThe modem interface driver in Samsung Android fails to bounds-check a buffer in set_skb_priv(), allowing an out-of-bounds read. The read can derefere…KEVEPSS 0.64%analysed6.7CVE-2021-25371Samsung Android DSP driver allows loading arbitrary ELF librariesThe DSP driver in Samsung Android devices before SMR Mar-2021 Release 1 permits loading of arbitrary ELF libraries inside the DSP. This breaks the in…KEVEPSS 0.80%analysed6.7CVE-2021-25372Samsung Android DSP driver improper boundary check allows out-of-bounds memory accessThe Samsung DSP driver in Android contains an improper boundary check that permits out-of-bounds memory access. The flaw is fixed in SMR Mar-2021 Rel…KEVEPSS 0.80%analysed6.4CVE-2021-25395Samsung Android MFC charger driver race condition bypasses signature checkA race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters…KEVEPSS 0.37%analysed6.4CVE-2021-25394Samsung Android MFC charger driver use-after-free via race conditionThe MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but…KEVEPSS 0.40%analysed5.5CVE-2021-25489Samsung Android modem driver format string bug causes kernel panicSamsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA…KEVEPSS 0.53%analysed

Source: NIST National Vulnerability Database (record CVE-2021-25337), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.