CVE-2025-21078: Samsung Smart Switch
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications.
Affected products
- Samsung Smart Switch: before 3.7.68.6 (fixed in 3.7.68.6)
Published 2025-11-05. Last modified 2026-06-17.