CVE-2025-21060: Samsung Smart Switch

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.

Affected products

  • Samsung Smart Switch: before 3.7.67.2 (fixed in 3.7.67.2)

Published 2025-10-10. Last modified 2026-10-08.