Vulnerability record · CVE-2021-25394 · published 11 June 2021
CVE-2021-25394: Samsung Android MFC charger driver use-after-free via race condition
Samsung · Android
The MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but only after a radio privilege has already been compromised, so it is a privilege-escalation step rather than an initial entry point.
Description
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed exploitation, but the high privilege prerequisite and local attack vector limit broad exposure.
What it is
The MFC charger driver in Samsung Android contains a use-after-free that can be triggered through a race condition. It allows an arbitrary write, but only after a radio privilege has already been compromised, so it is a privilege-escalation step rather than an initial entry point.
Impact
An attacker who already holds radio-level privileges can corrupt freed memory and perform an arbitrary write, potentially escalating to kernel or higher-level code execution on the device.
Attack surface
The flaw is local (AV:L) and requires high privileges (PR:H) with no user interaction (UI:N), meaning it is reached from code already running with radio privilege on the device, not remotely.
Exploitation
CVE-2021-25394 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation, though EPSS 30-day probability is low at roughly 0.4 percent and no ransomware use is documented.
What to do
- Apply the Samsung SMR MAY-2021 Release 1 (or later) security update to affected devices.
- If updates are unavailable, discontinue use of the affected product per CISA guidance.
- Restrict and monitor radio-privilege processes and interfaces to limit the preconditions for this flaw.
- Track device patch compliance and enforce minimum firmware baselines for Samsung Android devices.
Detection
- Monitor for anomalous writes or crashes originating from the MFC charger driver in kernel logs.
- Alert on unexpected radio-privilege process behavior or privilege transitions on Samsung devices.
- Correlate device telemetry with known exploitation indicators for CVE-2021-25394 where available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25394 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Race Condition Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25394 | US Government Resource |
Track CVE-2021-25394 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25394), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.