CVE-2025-66363

7.5

Samsung · Exynos 2200

A memory initialization vulnerability exists in the LBS component of the Samsung Exynos 2200 mobile processor, which can be triggered via DL NAS Transport messages.

Executive summary

A critical memory initialization flaw in the Samsung Exynos 2200 processor allows unauthenticated attackers to cause a denial of service.

Vulnerability

The vulnerability involves a failure to perform adequate memory initialization within DL NAS Transport messages, allowing an unauthenticated remote attacker to trigger a crash or system instability.

Business impact

The flaw carries a CVSS score of 7.5, reflecting its high impact on system availability. Successful exploitation could lead to persistent denial of service conditions, forcing device reboots and disrupting critical mobile communications or enterprise functions relying on the affected hardware.

Remediation

Immediate Action: Consult the official Samsung semiconductor security updates page to identify and apply the necessary firmware or security patches for your specific device model.

Proactive Monitoring: Monitor device logs for unexpected system reboots or crash reports that correlate with the reception of network-layer transport messages.

Compensating Controls: While hardware-level flaws are difficult to mitigate via software, ensure that network-level traffic filtering or mobile device management (MDM) policies are active to restrict unnecessary incoming traffic where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for denial of service and the lack of authentication required, this vulnerability presents a significant risk to the availability of mobile devices utilizing the Exynos 2200 processor. Organizations and users should prioritize checking for vendor-supplied firmware updates and applying them immediately upon release to ensure system stability and integrity.

More Samsung CVEs

Sources