Samsung Android
cpe:2.3:o:samsung:android:*:*:*:*:*:*:*
- >= 13, < 13.0.0.0
- >= 14, < 14.0.0.0
- >= 15, < 15.0.0.0
A vulnerability exists in the fingerprint trustlet of Samsung Mobile devices running Android versions 13, 14, and 15, prior to the June 2025 Security Maintenance Release. This vulnerability allows local privileged attackers to access an auth_token due to improper access control in the fingerprint trustlet.
Exploitation of this vulnerability allows local privileged attackers to retrieve an auth_token from the fingerprint trustlet.
Users can apply the June 2025 Security Maintenance Release to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.