CVE-2020-28343
published 2020-11-08CVE-2020-28343: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.3th percentile
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung ID is SVE-2020-18610 (November 2020).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7x8-xvj5-5349: An issue was discovered on Samsung mobile devices with P(9
ghsa_unreviewed·2022-05-24
CVE-2020-28343 [HIGH] CWE-787 GHSA-c7x8-xvj5-5349: An issue was discovered on Samsung mobile devices with P(9
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung ID is SVE-2020-18610 (November 2020).
Project0
An iOS hacker tries Android - Project Zero
project_zero·2020-12-01·CVSS 7.8
CVE-2017-2370 [HIGH] An iOS hacker tries Android - Project Zero
Written by Brandon Azad, when working at Project Zero
One of the amazing aspects of working at Project Zero is having the flexibility to direct my own research agenda. My prior work has almost exclusively focused on iOS exploitation, but back in August, I thought it could be interesting to try writing a kernel exploit for Android to see how it compares. I have two aims for this blog post: First, I will walk you through my full journey from bug description to kernel read/write/execute on the Samsung Galaxy S10, starting from the perspective of a pure-iOS security researcher. Second, I will try to emphasize some of the major security/exploitation differences between the two platforms that I have observed.
You can find the fully-commented exploit code attached in issue 2073.
In November
Project0
Project Zero RCA: CVE-2022-22265: Samsung NPU device driver double free in Android
project_zero·CVSS 5.0
CVE-2022-22265 [MEDIUM] Project Zero RCA: CVE-2022-22265: Samsung NPU device driver double free in Android
# CVE-2022-22265: Samsung NPU device driver double free in Android
Xingyu Jin, Android Security Research
## The Basics
**Disclosure or Patch Date:** Jan 01, 2022
**Product:** Samsung Android
**Advisory:** https://security.samsungmobile.com/securityUpdate.smsb
**Affected Versions:** Samsung Exynos with NPU, pre SMR-Jan-2022
**First Patched Version:** SMR-Jan-2022
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Seonung Jang of STEALIEN
## The Code
**Proof-of-concept:** N/A
**Exploit sample:** N/A
**Did you have access to the exploit sample when doing the analysis?** Yes
## The Vulnerability
**Bug class:** Double free
**Vulnerability details:**
There is a double free vulnerability in the Samsung NPU (`/dev/vertex10`) on the formats
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-08
Published