Security News > 2025 > January > Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
2025-01-10 15:39

Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity vulnerability, tracked as CVE-2024-49415 (CVSS score: 8.1), affects Samsung devices running Android versions 12, 13, and 14. "Out-of-bounds write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote


News URL

https://thehackernews.com/2025/01/google-project-zero-researcher-uncovers.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-12-03 CVE-2024-49415 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0
Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.
network
low complexity
samsung CWE-787
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 103 257 4348 4734 747 10086
Samsung 1617 134 379 413 75 1001