CVE-2025-21070: Medium severity Samsung Notes vulnerability
Published Oct 10, 2025
·Updated
Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.
Affected Software
2 affected components
Samsung Notes<4.4.30.63
Samsung Notes<4.4.30.63
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Notesto a version that resolves this vulnerability.Fixed in 4.4.30.63
Event History
Oct 10, 2025
CVE Published
via MITRE·06:33 AM
Data Sourced
via MITRE·06:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21070?
CVE-2025-21070 is considered a high-severity vulnerability due to the potential for local attackers to exploit out-of-bounds memory writes.
2
How do I fix CVE-2025-21070?
To mitigate CVE-2025-21070, users should update Samsung Notes to version 4.4.30.63 or later.
3
Who is affected by CVE-2025-21070?
CVE-2025-21070 affects all versions of Samsung Notes prior to version 4.4.30.63.
4
What type of vulnerability is CVE-2025-21070?
CVE-2025-21070 is classified as an out-of-bounds write vulnerability.
5
Can CVE-2025-21070 be exploited remotely?
No, CVE-2025-21070 can only be exploited by local attackers with access to the device.