CVE-2025-58482
7.3Samsung · MotionPhoto
An improper access control vulnerability in the MPLocalService component of Samsung MotionPhoto allows local attackers to initiate a privileged service.
Executive summary
A high-severity local privilege escalation vulnerability in Samsung MotionPhoto allows attackers to execute privileged services, posing a significant risk to device integrity.
Vulnerability
This flaw is an improper access control issue (CWE-284) within the MPLocalService. It allows a local attacker with low privileges to trigger a privileged service, effectively bypassing intended security constraints.
Business impact
The ability for a local attacker to start a privileged service can lead to full system compromise, unauthorized data access, or the execution of malicious code with elevated permissions. Given the CVSS score of 7.3, this represents a significant risk to the confidentiality, integrity, and availability of affected Samsung mobile devices.
Remediation
Immediate Action: Update Samsung MotionPhoto to version 4.1.51 or later via the official Samsung security update channels.
Proactive Monitoring: Security teams should monitor device logs for unexpected service start requests or unauthorized attempts to interact with local system services.
Compensating Controls: Ensure that device-level security policies are strictly enforced and limit the installation of untrusted or third-party applications that could serve as an initial entry point for local attacks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability in Samsung MotionPhoto presents a serious risk of local privilege escalation that could lead to total system compromise. Organizations and individual users should prioritize the application of the 4.1.51 update provided by Samsung to neutralize this threat. Given the potential for elevated access, failure to patch leaves the device susceptible to malicious local actors.