CVE-2025-20924: Medium severity samsung notes vulnerability
Published Mar 6, 2025
·Updated
Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.
Affected Software
2 affected components
Samsung Notes<4.4.26.71
Samsung Notes<4.4.26.71
Event History
Mar 6, 2025
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20924?
CVE-2025-20924 has a high severity due to its improper access control that allows unauthorized data access across user profiles.
2
How do I fix CVE-2025-20924?
To fix CVE-2025-20924, update Samsung Notes to version 4.4.26.71 or later.
3
Who is affected by CVE-2025-20924?
Users of Samsung Notes versions prior to 4.4.26.71 are affected by CVE-2025-20924.
4
What type of attack does CVE-2025-20924 enable?
CVE-2025-20924 enables physical attackers to access sensitive data across multiple user profiles.
5
Is there a workaround for CVE-2025-20924?
There is no official workaround for CVE-2025-20924; updating to the latest version is recommended.