CVE-2025-20975: Samsung Mobile Aodservice

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.

Affected products

Published 2025-05-07. Last modified 2026-06-17.