External risk intelligence

Samsung Exynos SMS Parsing Stack Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2025-54328

The vulnerability exists in mobile and wearable processor modems and involves the processing of SMS RP-DATA messages. As these components are designed to receive cellular network traffic directly from the air interface in normal operation, they constitute a public-facing service that is reachable by design over mobile networks.

Buffer Overflow

Samsung Exynos 980 Firmware

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Samsung's Exynos mobile and modem processors, specifically related to how they process certain SMS messages. This issue could allow for significant compromise of affected devices, potentially impacting confidentiality, integrity, and availability.

  • Flaw in SMS processing on Samsung processors.
  • Critical risk to device security and data.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target devices with vulnerable Samsung processors by sending specially crafted SMS messages. The device's SMS processing component, specifically when handling RP-DATA messages, contains a flaw that an attacker can trigger. Successfully triggering this flaw could allow an attacker to compromise the device's integrity and confidentiality.

  • No authentication or network access required.
  • Triggered by specially crafted SMS messages.
  • Potential for data compromise and system control.

Live Threat

Current exploitation, exposure, and threat context

A stack-based buffer overflow vulnerability in Samsung modem and processor firmware could allow an attacker to impact service behavior. This vulnerability occurs when parsing SMS RP-DATA messages.

  • Affected system firmware.
  • SMS parsing could trigger overflow.
  • Potential for service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world action for this vulnerability likely falls to teams managing Samsung Exynos mobile and wearable processors, including firmware, platform, and potentially mobile device management teams. The immediate first step is to identify all instances of the affected Exynos processors across your environment, confirm their network exposure and business criticality, and then locate the accountable asset owner to plan a coordinated remediation strategy.

  • Own by firmware, platform, and device management teams.
  • Verify network exposure and business criticality.
  • Coordinate with asset owners for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Samsung Exynos processor and its role?

Samsung Exynos processors are chipsets found in mobile phones, wearables, and modems. They serve as the central hardware and communication controllers for these devices, managing essential functions like cellular connectivity. Many of the specified models—such as the Exynos 2400, W1000, or various Modem versions—handle core system tasks, including the intake and processing of cellular network data like SMS messages.

What does CWE-121 mean for CVE-2025-54328?

CWE-121 refers to a stack-based buffer overflow. In the context of this vulnerability, it means the software responsible for parsing SMS RP-DATA messages lacks sufficient checks when copying data into a fixed-length memory area known as the stack. If a specially crafted message is sent, it can overflow this area, potentially overwriting adjacent memory and allowing the system to behave in unintended, often insecure ways.

How is this vulnerability triggered?

The flaw is triggered when the processor's modem firmware receives and attempts to parse a specially crafted SMS RP-DATA message. Because the issue exists within the processing logic of these incoming messages, it does not require the user to open a message or interact with it. Simply receiving the data packet over the cellular network is sufficient to initiate the vulnerable parsing process.

Is my device exposed to this threat?

According to Halo Surface Signal, this vulnerability is considered externally reachable by design. Because these processors are built to receive cellular traffic directly from the air interface, any device using an affected Exynos processor is effectively exposed to network-based attacks. The vulnerability does not require authentication, making it a critical concern for any device actively connected to a mobile network.

What should I do to address this vulnerability?

Begin by identifying all hardware or mobile devices in your environment that utilize the listed Exynos processors. Verify their current firmware versions and cross-reference them with official Samsung security updates. Since this involves low-level processor firmware, coordinate with your device management or platform engineering teams to track and apply the necessary manufacturer-provided patches as they become available.

References