CVE-2025-21035
Samsung Calendar ≤ 12.5.06.5
CVSS Score v3.1
4.6
Click a component to see what it means
Raw vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.0022
13th percentile
Summary
CVE-2025-21035 is a medium-severity an unspecified weakness vulnerability in Samsung Calendar. Its CVSS base score is 4.6 (Medium).
Operationally, ranked at the 13th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-27692
Vulnerability Data
Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2023-21464Same product: Google Android
CVE-2023-30678Same product: Google Android
CVE-2023-21482Same product: Google Android
CVE-2025-20926Same product: Google Android
CVE-2024-34599Same product: Google Android
CVE-2023-21462Same product: Google Android
CVE-2023-42579Same product: Google Android
CVE-2024-20840Same product: Google Android
CVE-2023-21463Same product: Google Android
CVE-2024-20839Same product: Google Android
Affected Assets
samsung
calendar
≤ 12.5.06.5 · ≤ 12.6.01.12
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.