CVE-2025-58487
BaseFortify
Publication date: 2025-12-02
Last updated on: 2025-12-03
Assigner: Samsung Mobile
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | account | to 15.5.01.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper authorization issue in Samsung Account versions prior to 15.5.01.1. It allows a local attacker to launch arbitrary activities with Samsung Account privileges, potentially enabling unauthorized actions within the Samsung Account environment.
How can this vulnerability impact me? :
The vulnerability could allow a local attacker to execute arbitrary activities with Samsung Account privileges, which may lead to unauthorized operations or disruptions. However, it does not impact confidentiality or integrity, only availability to some extent, as indicated by the CVSS score.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update Samsung Account to version 15.5.01.1 or later where the improper authorization issue is fixed.