CVE-2025-20940

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Apr 8, 2025

Summary

CVE-2025-20940 is a vulnerability affecting Samsung Device Health Manager Service. This issue arises from the improper handling of insufficient permissions, enabling local attackers to gain unauthorized access to the provider component in the SDMHS before the SMR Apr-2025 Release 1. This vulnerability could potentially lead to privacy and security concerns, as attackers may be able to access sensitive information without proper authorization. Users are advised to update their devices to the latest release to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share