CVE-2020-25055

CRITICAL

Samsung Android O(8.x), P(9.0), Q(10.0) - Incorrect Authorization in Persona Service

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-18133 (August 2020).

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (4)
google/android 8.0
google/android 8.1
google/android 9.0
google/android 10.0
Published Aug 31, 2020
Tracked Since Feb 18, 2026