Improper Access Control in Samsung Mobile's SecSettings
CVE-2025-21049

5.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 October 2025

What is CVE-2025-21049?

The vulnerability in Samsung Mobile's SecSettings arises from improper access control mechanisms that allow local attackers to gain unauthorized access to sensitive information. This issue is triggered by user interaction, making it essential for users to be aware of their app usage to mitigate potential exposure until a patch is applied. Affected versions include those prior to the SMR Oct-2025 Release 1.

Affected Version(s)

Samsung Mobile Devices SMR Oct-2025 Release in Android 15, 16

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21049 : Improper Access Control in Samsung Mobile's SecSettings