CVE-2025-20968: Samsung Gallery

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.

Affected products

  • Samsung Gallery: before 14.5.10.3 (fixed in 14.5.10.3); before 14.5.09.3 (fixed in 14.5.09.3); before 15.5.04.5 (fixed in 15.5.04.5)

Published 2025-05-07. Last modified 2026-06-17.