CVE-2020-25055: Google Android

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-18133 (August 2020).

Affected products

  • Google Android: version 8.0 only; version 8.1 only; version 9.0 only; version 10.0 only

Published 2020-08-31. Last modified 2026-06-17.