CVE-2021-25394

CVE Published 2021-06-11
Related CWE(s) CWE-416: Use After Free, CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Related Vendor(s) google
Related Product(s) android
Exploitation Reported (CISA KEV) 2023-06-29
CVSS 3 Base Score 6.4 (MEDIUM)
CVSS 3 Attack Complexity HIGH
CVSS 3 Attack Vector LOCAL

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References