Vulnerability record · CVE-2021-25337 · published 4 March 2021
CVE-2021-25337: Samsung clipboard service access control flaw exposes local files
Samsung · Android
Samsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or write certain local files. The flaw is rated high severity (CVSS 7.1) and was added to CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Description
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Automated analysis
high priorityHigh CVSS severity plus confirmed inclusion in CISA KEV indicates real-world exploitation, though the local vector and required user interaction limit mass exploitation.
What it is
Samsung mobile devices before SMR Mar-2021 Release 1 have improper access control in the clipboard service, letting untrusted applications read or write certain local files. The flaw is rated high severity (CVSS 7.1) and was added to CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Impact
An attacker-controlled app can read or write files it should not reach, giving access to potentially sensitive local data and the ability to tamper with files. The CVSS vector shows high confidentiality and integrity impact with no availability impact.
Attack surface
The vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the user must install or launch a malicious app on the device. No network or remote vector is described.
Exploitation
The record is listed in CISA KEV with a due date of 2022-11-29, indicating known exploitation in the wild. EPSS is low at roughly 2.8 percent for the next 30 days, and no ransomware use is documented.
What to do
- Apply the Samsung SMR Mar-2021 Release 1 or later security update to affected devices.
- Enforce a policy requiring current Samsung security patch levels on managed mobile devices.
- Restrict installation of apps to trusted sources and review app permissions on clipboard access.
- Monitor vendor advisories for any follow-up fixes or revised patch guidance.
Detection
- Audit managed devices for security patch level below SMR Mar-2021 Release 1.
- Review app inventories for untrusted or sideloaded applications with clipboard or file access permissions.
- Monitor for anomalous file read or write activity by non-system apps on affected devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25337 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Samsung Mobile Devices Improper Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25337 | US Government Resource |
Track CVE-2021-25337 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25337), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.