Impact
The vulnerability is an access control flaw (CWE‑863) that allows a local attacker with device access to modify Settings in such a way that background data usage for applications can be disabled. This change can interfere with app functionality that depends on background connectivity, potentially disrupting services and user experience. The impact is limited to configuration changes rather than critical system compromise.
Affected Systems
Samsung Mobile Devices running Android 13, 14, 15 or 16 with SMR releases prior to Mar‑2026 Release 1. The problem exists in all CPEs listed that are before this release, including multiple monthly and quarterly SMR updates across those Android versions.
Risk and Exploitability
CVSS base score 4.8 indicates low to moderate severity. EPSS <1% indicates a low probability that the vulnerability will be exploited in the wild. It is not listed in the CISA KEV catalogue. Because the flaw requires local access to the device, the attack vector is a local attacker; users should ensure devices are promptly updated when the vendor releases a fix.
OpenCVE Enrichment