CVE-2025-20926: Medium severity android my files vulnerability
Published Mar 6, 2025
·Updated
Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege.
Affected Software
3 affected components
Android My Files<15.0.07.5
All of the following
Samsung MyFiles<15.0.07.5
Google Android=14.0
Event History
Mar 6, 2025
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20926?
CVE-2025-20926 is classified as a moderate severity vulnerability due to its potential for local exploitation.
2
How do I fix CVE-2025-20926?
To fix CVE-2025-20926, update the My Files application to version 15.0.07.5 or later.
3
Who is affected by CVE-2025-20926?
CVE-2025-20926 affects users of My Files on Android devices running versions prior to 15.0.07.5.
4
What type of vulnerability is CVE-2025-20926?
CVE-2025-20926 is an information exposure vulnerability allowing unauthorized access to files.
5
Can CVE-2025-20926 be exploited remotely?
CVE-2025-20926 cannot be exploited remotely as it requires local access to the device.