CVE-2025-21050

7.1

Samsung · Mobile Devices

Improper input validation in the Samsung Contacts application allows a local attacker to bypass profile isolation and access data across multiple user profiles.

Executive summary

A critical local privilege escalation flaw in Samsung Mobile devices allows unauthorized cross-profile data access, posing a severe risk to user privacy and data security.

Vulnerability

This vulnerability involves improper input validation within the Contacts component, which permits a local, unauthenticated attacker to bypass security boundaries and access sensitive data residing in different user profiles.

Business impact

The exploitation of this flaw leads to significant data exposure, as it breaks the fundamental isolation between user profiles on Samsung devices. Given the CVSS score of 7.1, this is a high-severity issue that could result in the unauthorized disclosure of private contact information, potentially leading to identity theft or the compromise of sensitive corporate information stored within managed work profiles.

Remediation

Immediate Action: Update all affected Samsung mobile devices to the SMR October 2025 Release 1 or later to resolve the input validation flaw.

Proactive Monitoring: Security teams should monitor for unauthorized access patterns or suspicious application behavior that might indicate attempts to cross-reference contact databases.

Compensating Controls: Ensure that device-level security policies, such as Knox Workspace or Android Enterprise management profiles, are strictly enforced to minimize the surface area for local attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security oversight in the handling of cross-profile data permissions. Administrators should prioritize the deployment of the SMR October 2025 security patch across the mobile fleet immediately to prevent local attackers from exploiting this validation failure to exfiltrate sensitive data.

More Samsung CVEs

Sources