CVE-2018-21070

HIGH

Samsung Android N(7.x) and O(8.0) - Secure Boot Bypass via Missing Bootloader Integrity Check

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity check. The Samsung ID is SVE-2018-11552 (May 2018).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 8.4
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-354
Status published
Products (5)
google/android 7.0
google/android 7.1.0
google/android 7.1.1
google/android 7.1.2
google/android 8.0
Published Apr 08, 2020
Tracked Since Feb 18, 2026