Insufficient Privilege Management in Samsung Account by Samsung
CVE-2025-21076

5.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
5 November 2025

What is CVE-2025-21076?

A vulnerability in Samsung Account allows local attackers to potentially access sensitive data due to improper handling of insufficient permissions or privileges. This issue affects versions prior to 15.5.00.18 and necessitates user interaction to exploit successfully, raising concerns for user privacy and data security.

Affected Version(s)

Samsung Account 15.5.00.18

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21076 : Insufficient Privilege Management in Samsung Account by Samsung