
Cloud Vulnerability DB
A community-led vulnerabilities database
Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 affects Android versions 12, 13, and 14. The vulnerability was reported on November 12, 2024, and was assigned CVE-2025-20889 by Samsung Mobile (Mobile Communications Business of Samsung Electronics Co., Ltd.) (Samsung Mobile, CVE Details).
The vulnerability is classified as a Moderate severity issue that involves an out-of-bounds read vulnerability in the decoding process of malformed bitstream for smp4vtd component within libsthmbc.so library. The issue requires user interaction to be triggered (Samsung Mobile).
When exploited, this vulnerability allows local attackers to read arbitrary memory, potentially exposing sensitive information from the affected device's memory space (Samsung Mobile).
Samsung has addressed this vulnerability by adding proper input validation in the SMR Jan-2025 Release 1 security update. Users are advised to update their devices to this version or later to protect against this vulnerability (Samsung Mobile).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."