Android
cpe:2.3:o:samsung:android:*:*:*:*:*:*:*
- ~13
- ~14
- ~15
A vulnerability exists in the SpenGesture service on Samsung mobile devices, due to improper handling of permissions. This issue, present in several different versions of Android, allows local attackers to track the position of the S Pen.
Exploitation of this vulnerability enables local attackers to monitor S Pen movements, potentially leading to unauthorized access to user interactions or data associated with S Pen usage.
Users can apply the May 2025 Security Maintenance Release 1, which includes the necessary patch for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.