
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21034 is an out-of-bounds write vulnerability in the libsavsvc.so library on Samsung Android devices that allows local attackers to potentially execute arbitrary code. It affects Samsung Android versions 13, 14, 15, and 16 prior to the September 2025 Security Maintenance Release (SMR Sep-2025 Release 1). The vulnerability was published on September 3, 2025, with a patch released in the same month. It carries a CVSS v3.1 base score of 7.8 (High) (Samsung Security, Feedly).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the affected code in libsavsvc.so writes data beyond the boundaries of an allocated memory buffer. An attacker with local access and low privileges can trigger this memory corruption condition without requiring user interaction. The flaw resides in a Samsung-specific shared library (libsavsvc.so), which is part of Samsung's proprietary software stack on Galaxy devices. No public technical write-up or proof-of-concept code has been identified at this time (Samsung Security, Feedly).
Successful exploitation could allow a local attacker to execute arbitrary code in the context of the vulnerable library or process, potentially leading to full device compromise. The vulnerability has high confidentiality, integrity, and availability impact, meaning an attacker could access sensitive data, modify system state, or cause service disruption on affected Samsung Galaxy devices. Given the local attack vector, exploitation would typically require an attacker to already have a foothold on the device (e.g., via a malicious app or physical access) (Samsung Security, Feedly).
There is no public proof-of-concept exploit available, and no confirmed in-the-wild exploitation has been reported at the time of initial disclosure. However, subsequent reporting from security news outlets referenced Samsung zero-day activity on Galaxy devices around the same disclosure period, including exploitation via WhatsApp images, though direct attribution to CVE-2025-21034 specifically is not confirmed (CyberSecurityNews, Samsung GadgetHacks). The EPSS score is approximately 0.013% (very low), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has detection coverage for this CVE (detection ID 610730) (Feedly).
Samsung has addressed this vulnerability in the September 2025 Security Maintenance Release (SMR Sep-2025 Release 1) for Android versions 13, 14, 15, and 16. Users should apply the September 2025 security patch immediately via Settings > Software Update on affected Samsung Galaxy devices. As interim mitigations, organizations should restrict local user access to critical system libraries, implement application whitelisting to prevent untrusted apps from running, and monitor for suspicious local system activity (Samsung Security).
Security news outlets including CyberSecurityNews and Samsung GadgetHacks covered Samsung zero-day activity on Galaxy devices in the same timeframe, with some reports referencing exploitation via WhatsApp images on Samsung devices (CyberSecurityNews, Samsung GadgetHacks). Red Hot Cyber also covered Samsung's September 2025 security patch release, highlighting critical vulnerabilities addressed in the update (Red Hot Cyber). Community reaction has been moderate, with general advisories urging Samsung device users to apply the September 2025 patch promptly.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."