CVE-2025-20895: Samsung Galaxy Store
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
Affected products
- Samsung Galaxy Store: before 4.5.87.6 (fixed in 4.5.87.6)
Published 2025-02-04. Last modified 2026-06-17.