CVE-2025-21033
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-21033 is an improper access control vulnerability in the ContactProvider component of Samsung Android devices that allows local attackers to access sensitive contact-related information without elevated privileges. It affects Samsung Android versions 14.0 and 15.0 prior to the SMR Sep-2025 Release 1. The vulnerability was published on September 3, 2025, with a patch made available in the September 2025 Samsung Mobile Security Release. It carries a CVSS v3.1 base score of 5.5 (Medium) (Samsung Security, Feedly).

Technical details

The root cause is improper access control (CWE-284) in the ContactProvider component, a system-level content provider on Samsung Android devices responsible for managing contact data. A local attacker — one with an installed application or physical access — can query the ContactProvider without the necessary permissions, bypassing access restrictions and reading sensitive contact information. Exploitation requires only low-privilege local access with no user interaction needed, making it straightforward for a malicious app already installed on the device to silently exfiltrate contact data (Samsung Security, ENISA EUVD).

Impact

Successful exploitation results in unauthorized disclosure of sensitive contact information stored on the device, including names, phone numbers, email addresses, and other contact metadata. The impact is limited to confidentiality — there is no integrity or availability impact. While the scope is confined to the local device, contact data exposure could facilitate social engineering, targeted phishing, or further attacks against individuals in the victim's contact list (Samsung Security, ENISA EUVD).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation for CVE-2025-21033 specifically. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, Samsung Security).

Exploitation steps

  1. Reconnaissance: Identify a target Samsung Galaxy device running Android 14 or 15 without the SMR Sep-2025 patch applied.
  2. Malicious App Installation: Install a low-privilege Android application on the target device (e.g., via sideloading or a third-party app store) that does not declare the standard READ_CONTACTS permission.
  3. Query ContactProvider: From within the malicious app, issue a content resolver query directly to the ContactProvider URI (e.g., content://contacts/people or related URIs) that would normally require proper permission checks.
  4. Bypass Access Control: Due to the improper access control flaw, the ContactProvider returns contact data without enforcing the expected permission restrictions.
  5. Exfiltrate Data: The attacker's app collects and transmits the retrieved contact information (names, phone numbers, emails) to a remote server or stores it for later retrieval (Samsung Security, ENISA EUVD).

Indicators of compromise

  • Logs: Android system logs (logcat) showing repeated or unusual queries to content://contacts/ URIs from applications that do not declare READ_CONTACTS permission in their manifest.
  • Application Behavior: Installed apps making unexpected content resolver calls to ContactProvider without corresponding permission declarations in AndroidManifest.xml.
  • Network: Unusual outbound network connections from low-privilege apps shortly after device unlock or contact access events, potentially indicating data exfiltration.
  • File System: Unexpected files or databases containing contact data written to app-private storage directories of suspicious applications.

Mitigation and workarounds

Samsung has addressed this vulnerability in the SMR Sep-2025 Release 1, available for Samsung Android 14 and 15 devices. Users should apply the September 2025 security patch as soon as it becomes available for their device model. No configuration-based workaround is available; patching is the only remediation. As an interim measure, users should avoid installing applications from untrusted sources and review installed app permissions (Samsung Security, ENISA EUVD).

Community reactions

Samsung's September 2025 security bulletin received general coverage from technology media outlets, with articles noting the patch batch for Galaxy devices. Coverage from sites such as Aroged and Mixvale highlighted the September 2025 security fixes broadly, though CVE-2025-21033 was not individually spotlighted as a high-severity issue given its Medium CVSS rating (Aroged, Mixvale).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13097CRITICAL9.1
  • NixOS logoNixOS
  • python3-samba-test
NoYesAug 20, 2026
CVE-2026-11861HIGH8.1
  • NixOS logoNixOS
  • samba-common
NoYesAug 20, 2026
CVE-2026-73198HIGH7.5
  • NixOS logoNixOS
  • ctdb-ceph-mutex
NoYesAug 20, 2026
CVE-2026-73197HIGH7.5
  • NixOS logoNixOS
  • samba-test-libs-debuginfo
NoYesAug 20, 2026
CVE-2026-73196MEDIUM6.5
  • NixOS logoNixOS
  • samba-ldb-ldap-modules-debuginfo
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management