
Cloud Vulnerability DB
A community-led vulnerabilities database
Out-of-bounds write vulnerability (CVE-2025-21034) was discovered in Samsung's libsavsvc.so library prior to SMR Sep-2025 Release 1. The vulnerability was reported on April 24, 2025, and affects Android versions 13, 14, 15, and 16 (Samsung Mobile).
The vulnerability is classified as a High severity issue with a CVSS v3.1 base score of 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability is identified as CWE-787 (Out-of-bounds Write) and requires local access with low attack complexity. The vulnerability affects the libsavsvc.so component in Samsung mobile devices (NVD).
If exploited, this vulnerability allows local attackers to potentially execute arbitrary code on affected devices. The high CVSS score indicates significant potential impact on confidentiality, integrity, and availability of the system (Samsung Mobile).
Samsung has addressed this vulnerability in the SMR Sep-2025 Release 1 security update by adding proper input validation. Users of affected devices should update to this version as soon as it becomes available (Samsung Mobile).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."