Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.
CVE ID: CVE-2025-20968
CVSS Base Severity: HIGH
CVSS Base Score: 7.2
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vendor: Samsung Mobile
Product: Samsung Gallery
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 15.18% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)