CVE-2025-58486

Published Dec 2, 2025

Last updated 5 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-58486 is an improper input validation vulnerability found in Samsung Account versions prior to 15.5.01.1. This security flaw enables a local attacker to execute arbitrary scripts on affected devices. Such an exploit could potentially lead to unauthorized actions within the context of the Samsung Account application. The vulnerability stems from the Samsung Account application's failure to adequately validate and sanitize input data before processing it. This oversight allows malicious script content to be injected and subsequently executed within the application's security context. Samsung has since released an update, addressing this issue in Samsung Account version 15.5.01.1.

Description
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
Source
mobile.security@samsung.com
NVD status
Analyzed
Products
account

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.