CVE-2025-20996
BaseFortify
Publication date: 2025-06-04
Last updated on: 2025-10-28
Assigner: Samsung Mobile
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | smart_switch | to 3.7.64.10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper authorization issue in the Smart Switch software installed on non-Samsung devices before version 3.7.64.10. It allows local attackers to read data with the privileges of the Smart Switch application. Exploiting this vulnerability requires user interaction to trigger it.
How can this vulnerability impact me? :
An attacker with local access could exploit this vulnerability to read sensitive data accessible by the Smart Switch application, potentially leading to data exposure. Since it requires user interaction, the risk depends on the user's actions, but the confidentiality of data could be compromised.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update Smart Switch on your non-Samsung device to version 3.7.64.10 or later. Avoid local attacker access and be cautious with user interactions that could trigger the vulnerability.