CVE-2025-21035: Samsung Calendar
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.
Affected products
- Samsung Calendar: before 12.5.06.5 (fixed in 12.5.06.5); before 12.6.01.12 (fixed in 12.6.01.12)
Published 2025-09-03. Last modified 2026-06-17.