First published: Tue Feb 04 2025(Updated: )
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android Application Components | <SMR Feb-2025 Release 1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-20906 is classified as a high severity vulnerability due to the potential for local attackers to enable ADB.
To fix CVE-2025-20906, update your Android application components to the SMR Feb-2025 Release 1 or later.
CVE-2025-20906 affects Android operating systems prior to SMR Feb-2025 Release 1.
CVE-2025-20906 cannot be exploited remotely and requires local access to the device.
Users may be at risk of unauthorized access or control of their devices if CVE-2025-20906 is not mitigated.