Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
References
| Link | Resource |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-02-04 08:15
Updated : 2025-03-25 06:15
NVD link : CVE-2025-20886
Mitre link : CVE-2025-20886
CVE.ORG link : CVE-2025-20886
JSON object : View
Products Affected
samsung
- android
CWE
CWE-922
Insecure Storage of Sensitive Information
