Impact
Improper privilege management in the Settings application on Samsung Android devices before the February 2026 Release 1 allows local attackers to launch arbitrary activities using the elevated Settings privilege. This flaw can lead to execution of privileged code or configuration changes without the user’s consent, thereby compromising system integrity and potentially enabling further privilege escalation or unauthorized data access.
Affected Systems
Samsung Android 15.0 and 16.0 devices receiving firmware before SMR Feb-2026 Release 1 are affected. The issue is present across a range of SMR delivery releases such as smr-jan-2025-r1, smr-feb-2025-r1, smr-jan-2026-r1 and numerous other monthly and yearly updates across both Android 15 and 16 lines.
Risk and Exploitability
The vulnerability has a CVSS score of 8.4, indicating high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability, and it is not listed in the CISA KEV catalog. Nonetheless, a local adversary with access to the device can exploit the flaw. Attack feasibility is straightforward as it requires only local interaction and the firmware preceding the February 2026 update.
OpenCVE Enrichment