CVE-2025-21028: Medium severity ThemeManager ThemeManager vulnerability
Published Sep 3, 2025
·Updated
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
Affected Software
10 affected components
ThemeManager ThemeManager<SMR Sep-2025 Release 1
Samsung Android=15.0
Samsung Android=15.0-smr-apr-2025-r1
Samsung Android=15.0-smr-aug-2025-r1
Samsung Android=15.0-smr-jul-2025-r1
Samsung Android=15.0-smr-jun-2025-r1
Samsung Android=15.0-smr-mar-2025-r1
Samsung Android=15.0-smr-may-2025-r1
Samsung Android=16.0
Samsung Android=16.0-smr-aug-2025-r1
Event History
Sep 3, 2025
CVE Published
via MITRE·06:05 AM
Data Sourced
via MITRE·06:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21028?
CVE-2025-21028 is considered a high severity vulnerability due to its exploitation potential by local privileged attackers.
2
How do I fix CVE-2025-21028?
To fix CVE-2025-21028, upgrade ThemeManager to the version released in SMR Sep-2025 Release 1 or later.
3
Who is affected by CVE-2025-21028?
CVE-2025-21028 affects users of ThemeManager versions prior to SMR Sep-2025 Release 1.
4
What are the risks associated with CVE-2025-21028?
The risks include local privilege escalation, which could allow unauthorized access to restricted functionalities.
5
When was CVE-2025-21028 disclosed?
CVE-2025-21028 was disclosed in September 2025, highlighting issues in privilege management.