Vulnerability record · CVE-2021-25395 · published 11 June 2021
CVE-2021-25395: Samsung Android MFC charger driver race condition bypasses signature check
Samsung · Android
A race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters because signature verification is a security boundary, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation.
Description
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed exploitation via CISA KEV and high CIA impact, though the attack requires local access and prior radio privilege.
What it is
A race condition in the Samsung MFC charger driver, fixed prior to SMR MAY-2021 Release 1, lets a local attacker bypass a signature check. It matters because signature verification is a security boundary, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation.
Impact
An attacker who already holds radio privilege can bypass signature verification, potentially loading or executing code that should have been rejected. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached locally on the device; the vector is AV:L with PR:H, so the attacker must already hold radio privilege. No user interaction is required (UI:N).
Exploitation
CISA added it to the KEV catalog on 2023-06-29 with a remediation due date of 2023-07-20, so exploitation is confirmed; EPSS is low at 0.00366 (30-day probability), and no ransomware use is documented.
What to do
- Apply the Samsung SMR MAY-2021 Release 1 or later firmware update to affected devices.
- If updates are unavailable, discontinue use of the affected product per CISA guidance.
- Restrict or monitor which apps and processes can obtain radio privilege on managed devices.
- Track device fleet patch levels and prioritize unpatched Samsung Android devices.
Detection
- Monitor for unexpected signature verification failures or bypasses in MFC charger driver logs.
- Alert on processes acquiring radio privilege outside expected telephony components.
- Hunt for anomalous driver load or code execution events on Samsung Android devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25395 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "Samsung Mobile Devices Race Condition Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25395 | US Government Resource |
Track CVE-2021-25395 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25395), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.