CVE-2021-25476
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.1epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in Widevine's trusted application logging allows attackers to determine the memory layout of the TEE (Trusted Execution Environment), bypassing ASLR protection. This makes it easier to exploit other vulnerabilities within the secure processor.
Technical detail
Information disclosure vulnerability in Widevine TA log enables ASLR bypass within the TEE through memory layout information leakage. Attack vector requires local access to TEE logs; impact allows attackers to predict memory addresses for subsequent code execution attacks against the trusted application.
Summary generated and translated by AI from the official description.
An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected products
Samsung Mobile · Samsung Mobile Devices