CVE-2025-21064High· 8.8▾ TwilightImproper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
smart_switch < 3.7.67.2Upgrade past the affected range:
smart_switch 3.7.67.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-21060Medium· 5.5Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications
CVE-2025-21042High· 8.8Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
CVE-2025-21028Medium· 5.5Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
CVE-2026-19588Medium· 6.5Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
CVE-2026-19587Medium· 6.5Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
CVE-2025-58488Medium· 4.5Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information