
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21033 is an improper access control vulnerability in the ContactProvider component of Samsung Android devices that allows local attackers to access sensitive contact-related information without elevated privileges. It affects Samsung Android versions 14.0 and 15.0 prior to the SMR Sep-2025 Release 1. The vulnerability was published on September 3, 2025, with a patch made available in the September 2025 Samsung Mobile Security Release. It carries a CVSS v3.1 base score of 5.5 (Medium) (Samsung Security, Feedly).
The root cause is improper access control (CWE-284) in the ContactProvider component, a system-level content provider on Samsung Android devices responsible for managing contact data. A local attacker — one with an installed application or physical access — can query the ContactProvider without the necessary permissions, bypassing access restrictions and reading sensitive contact information. Exploitation requires only low-privilege local access with no user interaction needed, making it straightforward for a malicious app already installed on the device to silently exfiltrate contact data (Samsung Security, ENISA EUVD).
Successful exploitation results in unauthorized disclosure of sensitive contact information stored on the device, including names, phone numbers, email addresses, and other contact metadata. The impact is limited to confidentiality — there is no integrity or availability impact. While the scope is confined to the local device, contact data exposure could facilitate social engineering, targeted phishing, or further attacks against individuals in the victim's contact list (Samsung Security, ENISA EUVD).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation for CVE-2025-21033 specifically. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, Samsung Security).
READ_CONTACTS permission.content://contacts/people or related URIs) that would normally require proper permission checks.logcat) showing repeated or unusual queries to content://contacts/ URIs from applications that do not declare READ_CONTACTS permission in their manifest.AndroidManifest.xml.Samsung has addressed this vulnerability in the SMR Sep-2025 Release 1, available for Samsung Android 14 and 15 devices. Users should apply the September 2025 security patch as soon as it becomes available for their device model. No configuration-based workaround is available; patching is the only remediation. As an interim measure, users should avoid installing applications from untrusted sources and review installed app permissions (Samsung Security, ENISA EUVD).
Samsung's September 2025 security bulletin received general coverage from technology media outlets, with articles noting the patch batch for Galaxy devices. Coverage from sites such as Aroged and Mixvale highlighted the September 2025 security fixes broadly, though CVE-2025-21033 was not individually spotlighted as a high-severity issue given its Medium CVSS rating (Aroged, Mixvale).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."