CVE-2025-21066: High severity Samsung Notes vulnerability
Published Oct 10, 2025
·Updated
Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
Affected Software
2 affected components
Samsung Notes<4.4.30.63
Samsung Notes<4.4.30.63
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Notesto a version that resolves this vulnerability.Fixed in 4.4.30.63
Event History
Oct 10, 2025
CVE Published
via MITRE·06:33 AM
Data Sourced
via MITRE·06:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21066?
The severity of CVE-2025-21066 is considered high due to the potential for local attackers to access sensitive out-of-bounds memory.
2
How do I fix CVE-2025-21066?
To fix CVE-2025-21066, update Samsung Notes to version 4.4.30.63 or later.
3
Who is affected by CVE-2025-21066?
CVE-2025-21066 affects users of Samsung Notes prior to version 4.4.30.63.
4
What type of vulnerability is CVE-2025-21066?
CVE-2025-21066 is classified as an out-of-bounds read vulnerability.
5
Can CVE-2025-21066 be exploited remotely?
No, CVE-2025-21066 requires local access to the device to be exploited.