Cyber Resilience

CVE-2025-20966

Samsung Gallery ≤ 14.5.10.3

Published
07 May 2025
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 4.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0021 11th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2025-20966 is a medium-severity an unspecified weakness vulnerability in Samsung Gallery. Its CVSS base score is 4.6 (Medium).

Operationally, ranked at the 11th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-20967Same product: Samsung Android
CVE-2025-20969Same product: Samsung Android
CVE-2025-20968Same product: Samsung Android
CVE-2025-21048Same product: Samsung Android
CVE-2023-21476Same product: Samsung Android
CVE-2023-21435Same product: Samsung Android
CVE-2024-34610Same product: Samsung Android
CVE-2024-20874Same product: Samsung Android
CVE-2023-21442Same product: Samsung Android
CVE-2023-30679Same product: Samsung Android

Affected Assets

samsung
gallery
≤ 14.5.10.3 · ≤ 14.5.09.3 · ≤ 15.5.04.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References