Home

Description

Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.

PUBLISHED Reserved 2024-11-06 | Published 2025-09-03 | Updated 2025-09-03 | Assigner SamsungMobile




MEDIUM: 4.6CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-284: Improper Access Control

Product status

Default status
affected

12.5.06.5 in Android 14 and 12.6.01.12 in Android 15
unaffected

References

security.samsungmobile.com/...iceWeb.smsb?year=2025&month=09

cve.org (CVE-2025-21035)

nvd.nist.gov (CVE-2025-21035)

Download JSON