
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21005 is an improper access control vulnerability in the isemtelephony component of Samsung Android, affecting all versions prior to Android 15. It allows local attackers with low-privilege access to read sensitive information from the device. The vulnerability was published on July 8, 2025, with a patch available in Samsung's July 2025 security bulletin. It carries a CVSS v3.1 base score of 5.5 (Medium) (Samsung Advisory, Red Hat CVE).
The root cause is improper access control (CWE-284) in the isemtelephony component, a Samsung-specific telephony service layer present on Samsung Android devices. A local attacker with a low-privilege application or user account can bypass access restrictions to query or read sensitive telephony-related information that should be protected. No authentication bypass or remote vector is involved; the attack requires local execution on the device with minimal privileges and no user interaction (Samsung Advisory).
Successful exploitation results in a high confidentiality impact, potentially exposing sensitive data such as telephony configurations, call records, SIM-related information, or other personal data managed by the isemtelephony service. Integrity and availability are not affected. The scope is limited to the compromised device, with no evidence of lateral movement potential beyond local data exposure (Samsung Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012%, reflecting a very low probability of exploitation in the near term (Red Hat CVE, Samsung Advisory).
Samsung has addressed this vulnerability in Android 15 for Samsung devices, released as part of the July 2025 Samsung Mobile Security Update. Users should update their Samsung devices to Android 15 or apply the July 2025 security patch as soon as it becomes available for their device model. As a general precaution, limiting the installation of untrusted or low-privilege applications reduces exposure to local privilege-based attacks (Samsung Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."