
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21024 is a vulnerability in Samsung's Smart View application on Android that involves the use of implicit intents for sensitive communication, allowing local attackers to access sensitive information. It affects Smart View versions prior to Android 16 and was published on August 6, 2025. The vulnerability was assigned by Samsung Mobile and is patched in Android 16. NVD rates it at CVSS v3.1 base score of 5.5 (Medium), while Samsung's own scoring places it at 3.3 (Low) (Samsung Advisory, Red Hat CVE).
The root cause is classified as CWE-927 (Use of Implicit Intent for Sensitive Communication). In Android, implicit intents do not specify a target component, meaning any application registered to handle the intent can intercept it. Smart View's use of implicit intents to transmit sensitive data allows a malicious local application with low privileges to register an intent receiver and capture that information without requiring user interaction. The attack vector is local, requires low privileges, and has low attack complexity (Samsung Advisory).
Successful exploitation allows a local, low-privileged attacker to access sensitive information handled by the Smart View application, resulting in a high confidentiality impact with no effect on integrity or availability. The scope is limited to the affected device and does not facilitate direct lateral movement, but exposed data could include screen-sharing session details or device information transmitted by Smart View. The vulnerability does not enable code execution or data modification (Samsung Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Samsung Advisory, Red Hat CVE).
logcat) showing unexpected applications receiving intents from the Smart View package (com.samsung.android.smartview or similar).Samsung has addressed this vulnerability in Android 16, which replaces implicit intents with explicit intents for sensitive Smart View communications. Users should upgrade their Samsung devices to Android 16 or later as the primary remediation. As interim mitigations, administrators should restrict installation of untrusted applications on affected devices, enforce device management policies limiting local user access, and monitor for suspicious application installations (Samsung Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."