CVE-2022-22265

MEDIUM(5.0)KEV

Samsung Mobile Devices Use-After-Free Vulnerability

Description

CVE-2022-22265 is an improper check or handling of exceptional conditions vulnerability in the Samsung NPU (Neural Processing Unit) driver for Android devices that allows arbitrary memory write and code execution. The flaw exists in versions prior to the SMR (Security Maintenance Release) January 2022 Release 1. Although rated Medium severity with a CVSS score of 5.0, CISA has added CVE-2022-22265 to its Known Exploited Vulnerabilities catalog with a remediation deadline of October 9, 2023, confirming active exploitation in the wild against Samsung mobile devices. Organizations and users running Samsung Android devices should apply the January 2022 security update to mitigate this NPU driver vulnerability.

KEV Information

Vendor
Samsung
Product
Mobile Devices
Date Added
September 18, 2023
Due Date
October 9, 2023
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:LOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
0.8
Impact Score
3.7

CWEs

Affected Products

VendorProductVersion
googleandroid9.0; 10.0; 11.0; 12.0

Multiple CVSS Assessments

Source: [email protected](Secondary)
5.0
MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-703: Improper Check or Handling of Exceptional Conditions

CWE-703 describes a weakness where software does not properly anticipate or handle unusual or exceptional conditions during processing. In CVE-2022-22265, this manifests in Samsung's NPU driver, where insufficient validation of exceptional conditions allows an attacker to perform arbitrary memory writes and achieve code execution on the device's neural processing unit subsystem.

Learn more: CWE-703 — Improper Check or Handling of Exceptional Conditions

Impact Analysis

CVE-2022-22265 carries a CVSS v3.1 score of 5.0 (Medium severity), reflecting a constrained but real exploitation risk on Samsung Android devices. Attack Vector (Local): The vulnerability requires local access to the device, meaning the attacker must have already gained some level of access through a malicious application or physical device access. Attack Complexity (High): Exploitation requires specific conditions to be met, making the attack more difficult to execute reliably. Privileges Required (Low): Basic user-level privileges are sufficient to initiate the attack, such as those available to a standard Android application. User Interaction (Required): The victim must take some action, such as installing a malicious application, for the exploit to succeed. Scope (Changed): A successful exploit can affect resources beyond the vulnerable NPU driver component, potentially impacting the broader Android operating system and other system components. Confidentiality, Integrity, and Availability (all Low): While the direct impact per metric is limited, the ability to perform arbitrary memory writes and execute code on the NPU driver could serve as a stepping stone for further exploitation, such as privilege escalation or sandbox escape. Despite the Medium CVSS score, the confirmed active exploitation by CISA warrants prompt patching.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2022-22265 in the wild by adding it to the Known Exploited Vulnerabilities catalog, with a remediation deadline of October 9, 2023. Despite the relatively modest EPSS score of 0.18% (39.94th percentile), which suggests limited widespread exploitation, the CISA KEV listing confirms that targeted exploitation has occurred. No public exploit code or proof-of-concept was identified in the available references. The local attack vector and high complexity requirements suggest that exploitation of this Samsung NPU driver vulnerability likely occurs as part of targeted attack chains rather than broad opportunistic campaigns.

Remediation

  1. Apply the Samsung SMR January 2022 security update. Install the Security Maintenance Release (SMR) January 2022 Release 1 or later on all affected Samsung mobile devices. Refer to the Samsung security update bulletin for January 2022 for detailed instructions. CISA's KEV required action states: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
  2. Enforce mobile device management (MDM) policies. Use MDM solutions to ensure all managed Samsung devices are updated to the patched firmware version. Block enterprise network access for devices running firmware versions prior to the January 2022 SMR.
  3. Restrict application installation sources. Configure Samsung devices to only allow application installations from trusted sources (Google Play Store, enterprise app stores). Enable Google Play Protect and Samsung's built-in security scanning to detect potentially malicious applications that could exploit local vulnerabilities.
  4. Monitor for unusual device behavior. Watch for signs of NPU driver exploitation, including unexpected application crashes, unusual CPU/NPU utilization patterns, or anomalous process execution. Deploy mobile threat defense (MTD) solutions to detect exploitation attempts on managed devices.
  5. Implement defense-in-depth for mobile endpoints. Enable Samsung Knox security features, enforce device encryption, and configure secure boot to reduce the impact of kernel-level exploitation. Ensure exception handling and input validation best practices are followed in any custom applications interacting with device hardware.

Technical Details

CVE-2022-22265 is classified under CWE-703 (Improper Check or Handling of Exceptional Conditions), where Samsung's NPU (Neural Processing Unit) driver fails to properly validate or handle exceptional conditions during processing, leading to arbitrary memory write and code execution capabilities. The vulnerability is locally exploitable (AV:L) with high attack complexity (AC:H), requiring low privileges (PR:L) and user interaction (UI:R), such as installing a malicious application. Notably, the scope is changed (S:C), meaning a successful exploit within the NPU driver can affect resources beyond the driver itself, potentially impacting the broader system. The individual impact ratings for confidentiality, integrity, and availability are each Low (C:L/I:L/A:L), reflecting the constrained initial impact, but the arbitrary memory write primitive could be leveraged as part of a multi-stage exploit chain to achieve higher-impact outcomes such as kernel code execution or complete device compromise.

Frequently Asked Questions

Is CVE-2022-22265 being actively exploited?

Yes. CISA has added CVE-2022-22265 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, with a remediation deadline of October 9, 2023. The ransomware association is currently listed as unknown. The EPSS score of 0.18% suggests targeted rather than widespread exploitation.

What products are affected by CVE-2022-22265?

CVE-2022-22265 affects Samsung mobile devices running Android with NPU (Neural Processing Unit) driver versions prior to the SMR January 2022 Release 1. The vulnerability is specific to Samsung's NPU driver implementation and impacts devices equipped with Samsung's neural processing hardware.

How do I fix CVE-2022-22265?

Install the Samsung Security Maintenance Release (SMR) January 2022 Release 1 or any subsequent security update. Check the Samsung security update bulletin for January 2022 for your specific device model. Use MDM solutions to enforce updates across managed device fleets.

How severe is CVE-2022-22265?

CVE-2022-22265 is rated Medium severity with a CVSS v3.1 score of 5.0 out of 10. The EPSS score of 0.18% places it in the 39.94th percentile. Despite the moderate CVSS rating, CISA's confirmation of active exploitation elevates the urgency, particularly for organizations managing Samsung device fleets.

CVSS Score

5.0
MEDIUM(5.0)

EPSS Score

EPSS Score0.39%
EPSS Percentile32.5%

Dates

PublishedJanuary 10, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.