CVE-2025-21005
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-21005 is an improper access control vulnerability in the isemtelephony component of Samsung Android, affecting all versions prior to Android 15. It allows local attackers with low-privilege access to read sensitive information from the device. The vulnerability was published on July 8, 2025, with a patch available in Samsung's July 2025 security bulletin. It carries a CVSS v3.1 base score of 5.5 (Medium) (Samsung Advisory, Red Hat CVE).

Technical details

The root cause is improper access control (CWE-284) in the isemtelephony component, a Samsung-specific telephony service layer present on Samsung Android devices. A local attacker with a low-privilege application or user account can bypass access restrictions to query or read sensitive telephony-related information that should be protected. No authentication bypass or remote vector is involved; the attack requires local execution on the device with minimal privileges and no user interaction (Samsung Advisory).

Impact

Successful exploitation results in a high confidentiality impact, potentially exposing sensitive data such as telephony configurations, call records, SIM-related information, or other personal data managed by the isemtelephony service. Integrity and availability are not affected. The scope is limited to the compromised device, with no evidence of lateral movement potential beyond local data exposure (Samsung Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012%, reflecting a very low probability of exploitation in the near term (Red Hat CVE, Samsung Advisory).

Mitigation and workarounds

Samsung has addressed this vulnerability in Android 15 for Samsung devices, released as part of the July 2025 Samsung Mobile Security Update. Users should update their Samsung devices to Android 15 or apply the July 2025 security patch as soon as it becomes available for their device model. As a general precaution, limiting the installation of untrusted or low-privilege applications reduces exposure to local privilege-based attacks (Samsung Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management