CVE-2025-20996: Samsung Smart Switch

Medium severity, CVSS 5.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.

Affected products

  • Samsung Smart Switch: before 3.7.64.10 (fixed in 3.7.64.10)

Published 2025-06-04. Last modified 2026-06-17.