Improper Authorization Vulnerability in Samsung Health by Samsung
CVE-2025-21019

5.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
6 August 2025

What is CVE-2025-21019?

Samsung Health prior to version 6.30.1.003 contains an improper authorization vulnerability that can be exploited by local attackers. This flaw allows unauthorized access to sensitive data stored within the app, given that user interaction is a prerequisite for triggering the vulnerability. It highlights the importance of proper authorization mechanisms in applications to safeguard user information.

Affected Version(s)

Samsung Health 6.30.1.003

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.