CVE-2025-21037EPSS p3.6%

CVE-2025-21037CVE-2025-21037

samsung / notes

Description

Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability.

Scoring

CVSS 4.1 ()
VectorCVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS0.15% probability of exploitation · percentile 3.6% · 2026-10-05T12:00:23Z
Last modified2026-10-01
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.