CVE-2025-58349
A critical flaw in Samsung’s Exynos processors allows attackers to crash the baseband by sending specially crafted LTE MAC packets. The vulnerability can cause devices to become unresponsive or reboot unexpectedly. It affects a wide range of Exynos chips used in smartphones, wearables, and modems.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Samsung Exynos 980, 990, 850, 1080, 1280, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, and various Modem chips (5123, 5300, 5400) running the listed firmware versions.
Real-world impact
An attacker could send malicious LTE traffic to a device, causing the baseband to crash. This would lead to a denial‑of‑service condition, making the phone or wearable unusable until rebooted.
Why this severity
The CVSS score of 9.1 reflects that the flaw requires no authentication or user interaction, yet it can completely deny availability and compromise confidentiality by crashing the baseband. The high impact on availability and the lack of mitigations elevate the score to critical.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Apr 6, 2026 · Apr 6, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- semiconductor.samsung.com/support/quality-support/pro…vendor advisory
- semiconductor.samsung.com/support/quality-support/pro…vendor advisory