← Back

CVE-2025-21049

nvd nist
Published: Oct 10, 2025Modified: Oct 23, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: mobile.security@samsung.com (Secondary)

Description

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

Affected (11)

Products: Samsung: Android
1 product
Android
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Samsung
Version 15.0
Version 15.0 smr-apr-2025-r1
Version 15.0 smr-aug-2025-r1
Version 15.0 smr-jul-2025-r1
Version 15.0 smr-jun-2025-r1
Version 15.0 smr-mar-2025-r1
Version 15.0 smr-may-2025-r1
Version 15.0 smr-sep-2025-r1
Version 16.0
Version 16.0 smr-aug-2025-r1
Version 16.0 smr-sep-2025-r1

References (1)

Source: mobile.security@samsung.com
Vendor Advisory

Timeline

No history available yet.