Vulnerability in Samsung S Assistant Allows Local Attackers to Modify Itinerary Information
CVE-2025-21038

5.1MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
3 September 2025

What is CVE-2025-21038?

A vulnerability in Samsung's S Assistant prior to version 9.3.2 allows local attackers to exploit improper verification of intent via the ExceptionalBroadcastReceiver. This could enable malicious users to alter sensitive itinerary information, posing significant privacy risks to users.

Affected Version(s)

S Assistant 9.3.2

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.