CVE-2025-20938
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Apr 8, 2025
Summary
CVE-2025-20938 is a vulnerability affecting SamsungContacts prior to the SMR Apr-2025 Release 1. This issue involves improper access control, giving local attackers the ability to bypass security restrictions and access protected data residing within the SamsungContacts application. This vulnerability may result in unauthorized access to sensitive information, potentially causing privacy concerns for affected users. It is essential for Samsung to release a patch to address this issue promptly to mitigate any potential risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.