Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.
CVE ID: CVE-2025-20966
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.6
CVSS Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor: Samsung Mobile
Product: Samsung Gallery
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 3.73% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)