CVE-2025-58486Medium· 4.0▾ SunlitImproper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
account < 15.5.01.1Upgrade past the affected range:
account 15.5.01.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-58488Medium· 4.5Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information
CVE-2025-58485Medium· 5.5Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.
CVE-2025-58483Medium· 5.9Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.
CVE-2025-58479Medium· 4.3Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
CVE-2025-58478Medium· 4.3Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
CVE-2025-58477Medium· 4.3Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.