Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Information Disclosure in Samsung Galaxy S25 Smart Touch Call (CVE-2025-58488) Threatens Mobile Credential Security

A CVE‑2025‑58488 flaw in Samsung's Smart Touch Call app on Galaxy S25 phones can disclose stored credentials when a user visits a malicious link. The vulnerability is medium‑severity, requires user interaction, and has been patched by Samsung. Third‑party risk managers should verify patch deployment and tighten mobile controls.

LiveThreat™ Intelligence · 📅 March 24, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
zerodayinitiative.com

Information Disclosure in Samsung Galaxy S25 Smart Touch Call (CVE‑2025‑58488) Threatens Mobile Credential Security

What It Is – A medium‑severity (CVSS 5.9) information‑disclosure flaw in the Smart Touch Call app of Samsung Galaxy S25 devices. The bug stems from improper handling of URL parameters, allowing an attacker who can lure a user to a malicious page or file to retrieve stored credentials.

Exploitability – Remote exploitation is possible but requires user interaction (malicious link or file). No public exploit code has been released, but a proof‑of‑concept was demonstrated at Pwn2Own.

Affected Products – Samsung Galaxy S25 smartphones (Smart Touch Call application). Samsung has issued a security update.

TPRM Impact – Organizations that provision Samsung phones to employees, or that allow BYOD with Galaxy S25 devices, face a supply‑chain risk: credential leakage can lead to corporate account compromise, unauthorized access to internal apps, and downstream phishing attacks.

Recommended Actions –

  • Verify that all Galaxy S25 devices are running Samsung’s latest security patch (December 2025 update).
  • Enforce mobile device management (MDM) policies that block untrusted URLs and require app‑level whitelisting.
  • Conduct a rapid inventory of any Galaxy S25 units in use and prioritize patch deployment.
  • Review authentication logs for anomalous credential usage originating from mobile devices.
  • Update employee security awareness training to highlight the risk of clicking unknown links on mobile phones.

Source: Zero Day Initiative Advisory ZDI‑26‑223

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-223/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →