CVE-2025-21049
10.10.2025, 07:15
Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| samsung | android | 15.0 |
| samsung | android | 15.0:smr-apr-2025-r1 |
| samsung | android | 15.0:smr-aug-2025-r1 |
| samsung | android | 15.0:smr-jul-2025-r1 |
| samsung | android | 15.0:smr-jun-2025-r1 |
| samsung | android | 15.0:smr-mar-2025-r1 |
| samsung | android | 15.0:smr-may-2025-r1 |
| samsung | android | 15.0:smr-sep-2025-r1 |
| samsung | android | 16.0 |
| samsung | android | 16.0:smr-aug-2025-r1 |
| samsung | android | 16.0:smr-sep-2025-r1 |
𝑥
= Vulnerable software versions