CVE-2025-20966: Medium severity Samsung Gallery vulnerability
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20966?
CVE-2025-20966 has been classified as a high severity vulnerability due to improper access control allowing unauthorized data access.
How do I fix CVE-2025-20966?
To fix CVE-2025-20966, update the Samsung Gallery app to version 14.5.10.4 or later on Global Android 13, 14.5.09.4 or later on China Android 13, and 15.5.04.6 or later on Android 14.
Who is affected by CVE-2025-20966?
CVE-2025-20966 affects users of Samsung Gallery prior to the specified versions on Global and China Android 13 and Android 14.
What kind of data is exposed due to CVE-2025-20966?
Due to CVE-2025-20966, unauthorized physical attackers may access personal data across multiple user profiles.
When was CVE-2025-20966 disclosed?
CVE-2025-20966 was disclosed in May 2025.