CVE-2025-21058

7.3

Samsung · Mobile Routines

Improper access control in Samsung Mobile Routines allows local attackers to potentially execute arbitrary code with SystemUI privileges.

Executive summary

A local access control vulnerability in Samsung Mobile Routines enables an attacker to achieve arbitrary code execution with elevated SystemUI privileges.

Vulnerability

This is an improper access control vulnerability (CWE-284) that occurs within the Routines component. The vulnerability can be triggered by a local attacker with no prior authentication (PR:N) to achieve arbitrary code execution with SystemUI level permissions.

Business impact

The ability to execute code with SystemUI privileges represents a significant security breach, as this level of access grants the attacker control over critical device interface components. With a CVSS score of 7.3, this flaw is categorized as High, reflecting the potential for complete loss of confidentiality and integrity of the user interface and potential denial of service.

Remediation

Immediate Action: Update Samsung Mobile Routines to version 4.8.7.1 or later for Android 15, or version 4.9.6.0 or later for Android 16.

Proactive Monitoring: Review device logs for unusual process execution patterns or unauthorized attempts to interact with SystemUI components.

Compensating Controls: Ensure device screen locks and full disk encryption are active to limit the ability of unauthorized local actors to interact with the device interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of the elevated privileges obtainable through this vulnerability, it is imperative that users and administrators ensure Samsung Mobile Routines is updated to the specified patched versions. Organizations managing fleets of Samsung mobile devices should verify that firmware updates containing these fixes are deployed to all managed assets immediately to mitigate the risk of local privilege escalation.

More Samsung CVEs

Sources