Improper Export in Samsung NotificationHistoryImageProvider
CVE-2025-20955

5.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
7 May 2025

What is CVE-2025-20955?

The NotificationHistoryImageProvider in Samsung devices prior to the SMR May-2025 Release 1 contains an improper export issue that allows local attackers to gain unauthorized access to notification images. This vulnerability can facilitate privacy invasions, putting users' sensitive information at risk. Proper mitigations and updates are essential to safeguard user data against such local exploitation.

Affected Version(s)

Samsung Mobile Devices SMR May-2025 Release in Android 13, 14, 15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.