Multiple vulnerabilities in Samsung applications



Risk Medium
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2025-21076
CVE-2025-21077
CVE-2025-21078
CVE-2025-21079
CWE-ID CWE-264
CWE-20
CWE-330
Exploitation vector Network
Public exploit N/A
Vulnerable software
Account
Mobile applications / Apps for mobile phones

Samsung Email
Mobile applications / Apps for mobile phones

Samsung Smart Switch
Mobile applications / Apps for mobile phones

Samsung Members
Mobile applications / Apps for mobile phones

Vendor Samsung

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU118087

Risk: Low

CVSSv4.0: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21076

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local attacker to gain access to sensitive information on the system.

The vulnerability exists due to improper handling of insufficient permissions or privileges. A local attacker can gain access data in Samsung Account.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Account: before 15.5.00.18

CPE2.3 External links

https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=11


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to perform certain actions on the device.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Input validation error

EUVDB-ID: #VU118088

Risk: Low

CVSSv4.0: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21077

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A local attacker can launch arbitrary activity with Samsung Email privilege.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Samsung Email: before 6.2.06.0

CPE2.3 External links

https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=11


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to perform certain actions on the device.

The attacker would have to login to the system and perform certain actions in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Use of insufficiently random values

EUVDB-ID: #VU118089

Risk: Medium

CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2025-21078

CWE-ID: CWE-330 - Use of Insufficiently Random Values

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to use of insufficiently random value of secretKey. A remote attacker on the local network can access backup data from applications.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Samsung Smart Switch: before 3.7.68.6

CPE2.3 External links

https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=11


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to perform certain actions on the device.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Input validation error

EUVDB-ID: #VU118094

Risk: Medium

CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2025-21079

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can connect arbitrary URL and launch arbitrary activity with Samsung Members privilege.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Samsung Members: before 5.5.01.3

CPE2.3 External links

https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=11


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to perform certain actions on the device.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###