VYPR
Unrated severityNVD Advisory· Published Aug 31, 2020· Updated Aug 4, 2024

CVE-2020-25047

CVE-2020-25047

Description

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S Secure application does not enforce the intended password requirement for a locked application. The Samsung IDs are SVE-2020-16746, SVE-2020-16764 (August 2020).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Samsung mobile S Secure app on P(9.0) and Q(10.0) in China/India devices does not enforce password requirement for locked apps, bypassing user intent.

Vulnerability

On Samsung mobile devices running Android P(9.0) and Q(10.0) released in China and India, the S Secure application fails to enforce the intended password requirement for a locked application [1]. This flaw affects the software versions distributed in those specific regional markets, as identified by Samsung IDs SVE-2020-16746 and SVE-2020-16764 (August 2020).

Exploitation

An attacker with physical access to an unlocked device or the ability to launch the S Secure application can bypass the password prompt that is meant to restrict access to secured apps. No special network position or authentication is required beyond having the device in hand and being able to interact with the S Secure interface.

Impact

Successful exploitation allows the attacker to access the protected application content without providing the correct password. This defeats the confidentiality and access control provided by S Secure, potentially exposing sensitive data (e.g., private photos, messages, files) that the user intended to keep locked.

Mitigation

Samsung has not provided details of a fixed version in the available references [1]. Users should ensure their devices are updated with the latest security patches from Samsung, which may address this issue. No workaround is described in the references; the vendor's security update page [1] should be monitored for future releases.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.