PublicCVE

CVE-2025-20970

MEDIUM6.2JSON exportCreate alert

Description

Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.

CVSS breakdown

CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected products

  • Samsung Mobile / Bixby Vision3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 – 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15