Improper Access Control in LeAudioService Affects Samsung Devices
CVE-2025-21002

6.2MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
8 July 2025

What is CVE-2025-21002?

An improper access control vulnerability in LeAudioService prior to the SMR Jul-2025 Release 1 allows local attackers to exploit the system, enabling them to manipulate broadcasting Auracast. This flaw may lead to unauthorized access to sensitive operations, posing significant security risks.

Affected Version(s)

Samsung Mobile Devices SMR Jul-2025 Release in Android 14, 15

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21002 : Improper Access Control in LeAudioService Affects Samsung Devices