Impact
Improper access control in the Samsung Android SLocation service allows a local attacker to invoke privileged APIs that are normally restricted. The vulnerability is an instance of improper control over access to protected functionality, which can enable the attacker to perform actions such as reading sensitive data, modifying system settings, or otherwise compromising device integrity.
Affected Systems
Samsung Mobile Devices running Android 15.0 and 16.0 firmware builds before the SMR Jan-2026 Release 1 update are affected. The impacted builds include all monthly security rollups listed in the Common Platform Enumeration entries for Android 15.0 and Android 16.0, spanning from March 2025 through late 2025 and into early 2026.
Risk and Exploitability
The flaw is exploitable locally; an attacker must already have physical or logical access to the device to use it. The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of wild exploitation at present. The flaw is not listed in CISA KEV, suggesting no large‑scale exploitation is known. The attack vector is local access, inferred from the description which states "local attackers" can execute privileged APIs.
OpenCVE Enrichment