Samsung Mobile CocktailBarService Improper Permission Handling Vulnerability

Vulnerability

A vulnerability exists in the CocktailBarService prior to the SMR May-2025 Release 1, allowing local attackers to exploit insufficient permission management and access privileged APIs. This issue affects several different versions of Samsung Mobile software.

Impact

Exploitation of this vulnerability allows local attackers to use privileged APIs, potentially leading to unauthorized actions or access within the affected application or service.

Remediation

Users can update to the Samsung Security Maintenance Release (SMR) May-2025 Release 1, which includes the patch for this vulnerability. Details on the update can be found on the Samsung Mobile Security Update page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.