Access Control Flaw in One UI Home Affects Samsung Devices
CVE-2025-21032

5.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
3 September 2025

What is CVE-2025-21032?

An access control vulnerability exists in One UI Home versions prior to the September 2025 Release 1, enabling physical attackers to exploit conditions that allow them to bypass Kiosk mode. This breach can have significant implications for user data security and device integrity in scenarios where Kiosk mode is expected to enforce strict access controls.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2025 Release in Android 14, 15

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21032 : Access Control Flaw in One UI Home Affects Samsung Devices