Medium severity5.5NVD Advisory· Published Apr 9, 2025· Updated Jun 17, 2026
CVE-2025-20952
CVE-2025-20952
Description
Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:samsung:android:15.0:smr-feb-2025-r1:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:samsung:android:15.0:smr-feb-2025-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:15.0:smr-jan-2025-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:15.0:smr-mar-2025-r1:*:*:*:*:*:*
- Range: < SMR Apr-2025 Release 1
- Range: SMR Apr-2025 Release in Android 15
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/securityUpdate.smsbnvdVendor Advisory
News mentions
0No linked articles in our index yet.