November 8, 2022 · Applied Cybernetics Group
CVE-2021-25337 — Samsung Mobile Devices
Samsung Mobile Devices Improper Access Control Vulnerability
- Added to KEV
2022-11-08- Federal due date
2022-11-29- Vendor
- Samsung
- Product
- Mobile Devices
- EPSS
- 74.4th percentile (score 0.008, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-25337
CISA short description
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.
Required action
Apply updates per vendor instructions.