Improper Access Control in MotionPhoto by Samsung
CVE-2025-58482

7.3HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
2 December 2025

What is CVE-2025-58482?

The MotionPhoto application from Samsung is vulnerable due to improper access control in the MPLocalService component. This flaw allows local attackers to initiate a privileged service, potentially leading to unauthorized access or manipulation of sensitive data. Users are encouraged to upgrade to version 4.1.51 or later to mitigate this risk. For more details, visit Samsung's security page.

Affected Version(s)

MotionPhoto 4.1.51

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58482 : Improper Access Control in MotionPhoto by Samsung