Improper Access Control in Samsung Notes Affects User Data
CVE-2025-21036

5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
3 September 2025

What is CVE-2025-21036?

An improper access control vulnerability in Samsung Notes allows local privileged attackers to gain unauthorized access to exported note files. This exploitation requires user interaction, posing risks to user data confidentiality and integrity. Users must ensure they are using the latest version of Samsung Notes to mitigate this vulnerability.

Affected Version(s)

Samsung Notes 4.4.30.63

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21036 : Improper Access Control in Samsung Notes Affects User Data