Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2023-21492
Samsung Mobile Devices
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L H N U H N N 4.4 .0255 84.5 YES
AFFECTED
Product Versions Fixed
Samsung Mobile Devices Selected Android 11, 12, 13 devices – —
TIMELINE
Nov 14 Reserved by Samsung Mobile
May 4 Published (CNA: Samsung Mobile)
May 19 Added to CISA KEV, remediation due 2023-06-09
Description
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| November 14, 2022 | Reserved | Reserved by Samsung Mobile |
| May 4, 2023 | Published | Published (CNA: Samsung Mobile) |
| May 19, 2023 | KEV ADDED | Added to CISA KEV, remediation due 2023-06-09 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Samsung Mobile | Samsung Mobile Devices | — | Selected Android 11, 12, 13 devices | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-21492 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.