Vulnerability record · CVE-2021-25369 · published 26 March 2021
CVE-2021-25369: Samsung Android sec_log improper access control leaks kernel data
Samsung · Android
Samsung Android devices contain an improper access control flaw in the sec_log file that exposes sensitive kernel information to userspace. The issue was fixed in the SMR MAR-2021 Release 1 maintenance release. Because kernel memory contents can reveal addresses and internal state, the leak matters for weakening later exploitation steps.
Description
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityThe flaw is a local information leak rated CVSS 5.5, but its presence in CISA KEV signals real-world exploitation, raising it above a routine medium.
What it is
Samsung Android devices contain an improper access control flaw in the sec_log file that exposes sensitive kernel information to userspace. The issue was fixed in the SMR MAR-2021 Release 1 maintenance release. Because kernel memory contents can reveal addresses and internal state, the leak matters for weakening later exploitation steps.
Impact
A local attacker gains read access to sensitive kernel information, which can aid in defeating kernel protections and building further exploits. The flaw itself provides information disclosure, not code execution or privilege escalation.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so an attacker needs code already running on the device under a normal user context. No network or remote vector is described.
Exploitation
CVE-2021-25369 is listed in CISA KEV with a due date of 2022-11-29, indicating known exploitation, though the EPSS 30-day probability is low at roughly 1.1 percent. No ransomware campaign use is recorded.
What to do
- Apply the Samsung SMR MAR-2021 Release 1 or later security maintenance release to affected devices.
- Enforce timely Android security patch levels across managed Samsung fleets and block devices below the fixed SMR.
- Restrict installation of untrusted apps and limit local code execution paths on sensitive devices.
- Monitor vendor advisories for any follow-up fixes or revised patch guidance.
Detection
- Track device patch level and flag Samsung Android devices below SMR MAR-2021 Release 1.
- Monitor for suspicious local processes or apps attempting to read kernel log or sec_log interfaces.
- Correlate endpoint telemetry for information-disclosure behavior preceding privilege escalation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25369 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Samsung Mobile Devices Improper Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://security.samsungmobile.com | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25369 | US Government Resource |
Track CVE-2021-25369 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25369), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.