CVE-2025-21041: Medium severity Android Android vulnerability
Published Sep 3, 2025
·Updated
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
Affected Software
2 affected components
Android Android<16
Samsung Android<16.0
Event History
Sep 3, 2025
CVE Published
via MITRE·06:05 AM
Data Sourced
via MITRE·06:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21041?
CVE-2025-21041 is classified as a high severity vulnerability due to its potential to allow local attackers to access sensitive information.
2
How do I fix CVE-2025-21041?
To mitigate CVE-2025-21041, upgrade to Android version 16 or later where the issue has been addressed.
3
What kind of information is at risk in CVE-2025-21041?
CVE-2025-21041 risks exposing sensitive user data stored in the Secure Folder.
4
Who is affected by CVE-2025-21041?
Users of Android versions prior to 16 are affected by CVE-2025-21041.
5
Can CVE-2025-21041 be exploited remotely?
No, CVE-2025-21041 requires local access to the device to exploit the vulnerability.