CVE-2023-50807
Description
An out-of-bounds write in the heap of Samsung Exynos 9110, Modem 5123, and Modem 5300 allows remote code execution via unauthenticated 2G network packets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds write in the heap of Samsung Exynos 9110, Modem 5123, and Modem 5300 allows remote code execution via unauthenticated 2G network packets.
Vulnerability
An out-of-bounds write vulnerability in the heap exists in Samsung's wearable processor and modem chipsets: Exynos 9110, Exynos Modem 5123, and Exynos Modem 5300 [1][2]. The flaw is triggered by processing specially crafted 2G network packets without any authentication, leading to a heap overflow condition [2].
Exploitation
An attacker needs only proximity to a vulnerable device and the ability to transmit malicious 2G baseband frames. No authentication or user interaction is required. By sending crafted 2G signaling messages, the attacker can trigger the out-of-bounds write in the modem's heap [1][2].
Impact
Successful exploitation can lead to arbitrary code execution at the modem privilege level, potentially allowing the attacker to control the device's cellular communication, exfiltrate data, or pivot to the main application processor. The vulnerability is rated High severity [1][2].
Mitigation
Samsung has released security patches for the affected modems. Users should apply firmware updates from their device manufacturer or as provided via Samsung's product security update process [1]. No workarounds are available; disabling 2G on the device may reduce attack surface but may not fully mitigate the vulnerability.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Samsung/Wearable Processor and Modemsdescription
- Range: = Exynos Modem 5300
- Range: = Exynos Modem 5123
- Range: = Exynos 9110
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
0No linked articles in our index yet.