CVE-2025-20899: Samsung Mobile Pushnotification

Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14 allows local attackers to access sensitive information.

Affected products

Published 2025-02-04. Last modified 2026-06-17.