Out-of-Bounds Read Vulnerability in Samsung Notes
CVE-2025-21066

4MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 October 2025

What is CVE-2025-21066?

An out-of-bounds read vulnerability exists in the SPI decoder of Samsung Notes prior to version 4.4.30.63. This flaw allows local attackers to potentially access memory that lies outside the intended bounds, posing a data privacy risk. Affected users should update their Samsung Notes to the latest version to mitigate this vulnerability.

Affected Version(s)

Samsung Notes 4.4.30.63

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21066 : Out-of-Bounds Read Vulnerability in Samsung Notes