Samsung has patched three high-severity vulnerabilities in the Exynos NPU driver—CVE-2025-23099, CVE-2025-23103, and CVE-2025-23107—that could allow local privilege escalation on affected Galaxy devices. The flaws impact Samsung Galaxy S24+ devices running Android 14 and systems based on Exynos 1480 and 2400 platforms, and each issue is reachable by a malicious application running in the untrusted_app SELinux context with low privileges and no user interaction. Samsung assigned a CVSS v3.1 score of 7.8 to the bugs and released fixes through Product Security Updates in early June.
The vulnerabilities stem from missing length checks in multiple NPU driver paths, leading to out-of-bounds writes in kernel memory. CVE-2025-23099 involves queue preparation logic that can reuse smaller prior allocations while trusting larger attacker-controlled counts, CVE-2025-23103 arises from an unbounded loop counter in npu_queue_update that can exceed the allocated queue_list size, and CVE-2025-23107 affects fill_vs4l_buffer, which writes kernel-side buffer metadata into an undersized user-supplied structure. STAR Labs SG credited Billy Jheng Bing-Jhong, Muhammad Alifa Ramdhan, and Pan Zhenpeng with reporting the issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Samsung published CVE-2025-23095 and released a fix through its Product Security Update for a high-severity double-free flaw in the Exynos NPU driver. The bug could allow local privilege escalation to root from the untrusted_app SELinux context on Galaxy S24+ devices running Android 14 and multiple Exynos chipsets.
STAR Labs SG published advisories for CVE-2025-23103, CVE-2025-23107, and CVE-2025-23099, detailing out-of-bounds write bugs in the Samsung Exynos NPU driver. The disclosures described local privilege-escalation impact, affected Galaxy S24+ and Exynos 1480/2400 platforms, and technical root causes for each flaw.
Samsung released a patch for CVE-2025-23099 through its Product Security Update. The high-severity Exynos NPU driver flaw involved an out-of-bounds write caused by missing length checks and could lead to local privilege escalation.
Samsung released fixes for CVE-2025-23103 and CVE-2025-23107 through a Samsung Product Security Update. Both high-severity Exynos NPU driver flaws could enable local privilege escalation on Galaxy S24+ devices running Android 14 and Exynos 1480/2400 platforms.
STAR Labs SG reported CVE-2025-23103, an out-of-bounds write vulnerability in the Samsung Exynos NPU driver, to Samsung. The issue could allow local privilege escalation from the untrusted_app SELinux context on affected Galaxy S24+ devices and Exynos 1480/2400 platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.