Authentication Bypass Vulnerability in Galaxy Store by Samsung
CVE-2025-20895

3.2LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 February 2025

Summary

An authentication bypass vulnerability exists in the Galaxy Store prior to version 4.5.87.6, enabling physical attackers to exploit the Setupwizard. This flaw permits the installation of arbitrary applications, circumventing established restrictions and potentially leading to unauthorized access and installation of malicious software.

Affected Version(s)

Galaxy Store 4.5.87.6

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.