CVE-2025-20966

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:gallery:*:*:*:*:*:*:*:*
cpe:2.3:o:samsung:android:13.0:-:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:gallery:*:*:*:*:*:*:*:*
cpe:2.3:o:samsung:android:13.0:-:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:gallery:*:*:*:*:*:*:*:*
cpe:2.3:o:samsung:android:14.0:-:*:*:*:*:*:*

History

30 Jan 2026, 21:18

Type Values Removed Values Added
First Time Samsung android
Samsung
Samsung gallery
Summary
  • (es) El control de acceso inadecuado en Samsung Gallery anterior a la versión 14.5.10.3 en Android 13 global, 14.5.09.3 en Android 13 de China y 15.5.04.5 en Android 14 permite que atacantes físicos accedan a datos en múltiples perfiles de usuario.
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:samsung:gallery:*:*:*:*:*:*:*:*
cpe:2.3:o:samsung:android:13.0:-:*:*:*:*:*:*
cpe:2.3:o:samsung:android:14.0:-:*:*:*:*:*:*
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05 - Vendor Advisory

07 May 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 09:15

Updated : 2026-01-30 21:18


NVD link : CVE-2025-20966

Mitre link : CVE-2025-20966

CVE.ORG link : CVE-2025-20966


JSON object : View

Products Affected

samsung

  • android
  • gallery