Impact
An improper export of Android application components in Samsung Dialer before SMR Feb‑2026 Release 1 permits a local attacker on a Samsung Mobile Device to launch arbitrary activities with Dialer privileges. This behavior effectively grants local privilege escalation, allowing compromised applications to execute privileged code that could lead to unauthorized actions or data access within the Dialer process.
Affected Systems
Affected devices include Samsung Mobile Devices running Android 14.0 or Android 15.0 across all SMR releases listed in the CPE data (for example, smr‑jan‑2026‑r1 through smr‑sep‑2025‑r1). All SMRs released prior to SMR Feb‑2026 Release 1 are vulnerable; versions updated to or beyond that release are not.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1 % shows a very low historical exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers must be present locally on the device and exploit the exported components to trigger the privilege escalation; no remote access is required or known. Despite the low exploitation likelihood, the high impact warrants immediate patching.
OpenCVE Enrichment