CVE-2025-21037: Medium severity Samsung Notes vulnerability
Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Notesto a version that resolves this vulnerability.Fixed in 4.4.30.63
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21037?
CVE-2025-21037 has a moderate severity level due to its improper access control vulnerability.
How do I fix CVE-2025-21037?
To fix CVE-2025-21037, upgrade Samsung Notes to version 4.4.30.63 or later.
Who is affected by CVE-2025-21037?
Users of Samsung Notes versions prior to 4.4.30.63 are affected by CVE-2025-21037.
What type of attack does CVE-2025-21037 enable?
CVE-2025-21037 allows physical attackers to access data across multiple user profiles.
Is user interaction required to exploit CVE-2025-21037?
Yes, user interaction is required to trigger the CVE-2025-21037 vulnerability.