CVE-2021-25358
NixOS vulnerability analysis and mitigation

Overview

A vulnerability in Samsung mobile devices prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission through untrusted applications due to improper storage path of IMSI values (Samsung Mobile, MITRE CVE).

Technical details

The vulnerability has a CVSS v3.1 base score indicating local attack vector, low attack complexity, and low privileges required. The scope is unchanged, with low confidentiality impact and no integrity or availability impacts (NVD Report).

Impact

The primary impact of this vulnerability is unauthorized access to IMSI (International Mobile Subscriber Identity) values, which could potentially lead to privacy breaches and tracking of mobile device users (MITRE CVE).

Exploitability

The vulnerability can be exploited by local attackers through untrusted applications without requiring special permissions. The attack complexity is considered low, making it relatively straightforward to exploit (NVD Report).

Mitigation and workarounds

Samsung addressed this vulnerability in the SMR APR-2021 Release 1 security update. Users should update their devices to this version or later to protect against unauthorized IMSI access (Samsung Mobile).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management