Improper Access Control in LeAudioService by Samsung Electronics
CVE-2025-21001

6.2MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
8 July 2025

What is CVE-2025-21001?

An access control vulnerability in LeAudioService prior to the July 2025 Security Maintenance Release allows local attackers to disrupt Auracast broadcasting. This flaw raises concerns for users relying on the seamless audio transmission capabilities of their devices, potentially leading to unauthorized manipulation of audio services.

Affected Version(s)

Samsung Mobile Devices SMR Jul-2025 Release in Android 14, 15

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21001 : Improper Access Control in LeAudioService by Samsung Electronics