Impact
Improper export of Android application components in Samsung Assistant prior to version 9.3.10.7 allows a local attacker to access saved information, resulting in a breach of confidentiality for the device owner.
Affected Systems
Samsung Mobile users running Samsung Assistant versions earlier than 9.3.10.7 are vulnerable, as the flaw exists in all installations of the app that have not been updated to the patched release.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The CVE notes a local attack vector and does not mention remote exploitation; thus an attacker must gain local access to the device. The vulnerability is not included in the CISA KEV catalog.
OpenCVE Enrichment