Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction is required for triggering this vulnerability.
History

Fri, 07 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung account
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:*
Vendors & Products Samsung account

Thu, 06 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung notes
Vendors & Products Samsung
Samsung notes

Wed, 05 Nov 2025 06:00:00 +0000

Type Values Removed Values Added
Description Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction is required for triggering this vulnerability.
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published: 2025-11-05T05:40:57.790Z

Updated: 2025-11-07T14:26:14.798Z

Reserved: 2024-11-06T02:30:14.896Z

Link: CVE-2025-21076

cve-icon Vulnrichment

Updated: 2025-11-05T14:20:18.460Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-05T06:15:33.840

Modified: 2025-11-07T13:02:25.600

Link: CVE-2025-21076

cve-icon Redhat

No data.