Samsung is addressing a serious security vulnerability (CVE-2024-44068) that affects multiple Exynos processors , including the 9820, 9825, 980, 990, 850, and W920 series .

The issue arises from a Use-After-Free in the m2m scaler driver, which is responsible for handling hardware in multimedia, such as JPEG decoding.
Also read: Samsung One UI 7 based on Android 15, will be released in 2025
Hackers can execute arbitrary code with elevated privileges by exploiting errors in memory management and page references. Specifically, the driver may incorrectly handle page references when processing IOCTL calls, which can lead to virtual I/O pages being mapped to freed physical pages .
Researchers have confirmed that threat actors are actively exploiting this vulnerability, allowing malicious applications to gain elevated privileges on devices and compromising the entire system. Attacks have been observed executing arbitrary code via privileged camera server processes, with hackers attempting to hide their activities.
Affected devices
The vulnerability affects devices using the following Exynos processors:
Exynos 9820
Exynos 9825
Exynos 980
Exynos 990
Exynos 850
Exynos W920

See also: CISA added ScienceLogic SL1 vulnerability to the KEV Catalog
Samsung has issued security patches for October 2024, warning users to immediately update their firmware due to a vulnerability discovered by Google. This vulnerability was publicly disclosed on October 7, 2024, and experts are highlighting the importance of vulnerability management and keeping firmware up-to-date.
It is also recommended to deploy advanced threat detection solutions and strengthen network security. Users should check their settings for available updates.
Source: cybersecuritynews
