CVE-2021-25392
NixOS vulnerability analysis and mitigation

Overview

Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to access sensitive information via changing the path. The vulnerability, identified as CVE-2021-25392, affects Samsung devices running Samsung Dex and was discovered in early 2021 (MITRE CVE, NVD).

Technical details

The vulnerability exists in the notification policy file handling of Samsung DeX System UI (com.samsung.desktopsystemui). It allows attackers to steal notification policy configuration through improper path protection (Oversecured Blog, Samsung Mobile).

Impact

The vulnerability enables attackers to access sensitive information from user notifications, which could include chat descriptions from messaging apps like Telegram, folder information from Google Docs, and email details from Samsung Email and Gmail inboxes (Hacker News).

Mitigation and workarounds

Samsung addressed this vulnerability in the May 2021 Security Maintenance Release (SMR). Users should update their devices to a version with SMR MAY-2021 Release 1 or later to protect against this vulnerability (Samsung Mobile).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • firefox-x11
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox-x11
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management