Samsung UnifiedWFC Improper Intent Verification Vulnerability Allowing VoWiFi Manipulation

Vulnerability

A vulnerability exists in the UnifiedWFC application on select Android 13, 14, and 15 devices, prior to the May 2025 Security Maintenance Release. This vulnerability stems from improper verification of intents by the broadcast receiver, which allows local attackers to manipulate Voice over Wi-Fi (VoWiFi) related behaviors.

Impact

Exploitation of this vulnerability could disrupt or alter VoWiFi functionalities on the affected device.

Remediation

Users can update to the Samsung May 2025 Security Maintenance Release to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.