Data Access Vulnerability in Samsung Contacts Product
CVE-2025-21050

7.1HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 October 2025

What is CVE-2025-21050?

An improper input validation issue in the Samsung Contacts application prior to the SMR October 2025 Release 1 enables local attackers to exploit the system and gain unauthorized access to sensitive user data across multiple profiles. This vulnerability highlights the importance of robust input validation measures to mitigate potential data exposure risks.

Affected Version(s)

Samsung Mobile Devices SMR Oct-2025 Release in Android 13, 14, 15

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.