First published: Wed May 07 2025(Updated: )
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung SpenGesture service | <SMR May-2025 Release 1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-20962 is categorized as moderate due to potential local attacks leveraging insufficient permissions.
To fix CVE-2025-20962, update the Samsung SpenGesture service to the version released after SMR May-2025 Release 1.
CVE-2025-20962 affects users of the Samsung SpenGesture service versions before SMR May-2025 Release 1.
CVE-2025-20962 can facilitate local attacks enabling unauthorized tracking of the S Pen position.
Currently, there are no known workarounds for CVE-2025-20962; updating the software is the recommended action.