Improper Intent Verification in S Assistant by Samsung
CVE-2025-21040

5.1MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
3 September 2025

What is CVE-2025-21040?

A vulnerability has been identified in S Assistant, relating to the improper verification of intent by the ExternalBroadcastReceiver. This flaw, present in versions prior to 9.3.2, enables local attackers to potentially modify itinerary information, leading to unauthorized changes in user data. It is crucial for users to update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

S Assistant 9.3.2

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21040 : Improper Intent Verification in S Assistant by Samsung