VulnerabilityAnalyzed
CVE-2025-20895
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
MEDIUM 4.6EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.20% probability · 11th percentile
- CISA KEV
- Not listed
- Affected
- samsung/galaxy store
- Source
- mobile.security@samsung.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.