CVE-2025-20951

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Apr 8, 2025

Summary

CVE-2025-20951 is a vulnerability affecting the Galaxy Store prior to version 4.5.90.7. This issue involves an improper verification of intent by the broadcast receiver, enabling local attackers to write arbitrary files with the privilege level of the Galaxy Store. This weakness could potentially be exploited for malicious purposes, such as installing unauthorized applications or modifying existing ones. The vulnerability poses a significant risk and requires immediate attention from Samsung for a patch to be released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share