CVE-2025-62818
Out-of-Bounds Write in Samsung Exynos Processors via SMS Packet
Publication date: 2026-04-07
Last updated on: 2026-04-13
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_990_firmware | * |
| samsung | exynos_980_firmware | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_1080_firmware | * |
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1580_firmware | * |
| samsung | exynos_9110_firmware | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2400_firmware | * |
| samsung | exynos_2500_firmware | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w1000_firmware | * |
| samsung | exynos_modem_5400_firmware | * |
| samsung | exynos_modem_5300_firmware | * |
| samsung | exynos_modem_5123_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-62818 is a medium-severity vulnerability affecting Samsung Exynos processors and modems. It occurs due to an out-of-bounds write caused by a mismatch between the TP-UDHI (Transport Protocol User Data Header Indicator) and UDL (User Data Length) values when processing SMS TP-UD (Transport Protocol User Data) packets. This mismatch leads to improper handling of SMS data, which can cause memory corruption.
How can this vulnerability impact me? :
The vulnerability can lead to memory corruption in affected Samsung Exynos processors and modems when processing specially crafted SMS messages. This memory corruption could potentially be exploited to cause unexpected behavior, crashes, or possibly allow an attacker to execute arbitrary code, impacting the stability and security of the device.