Impact
URL redirection in Samsung Account versions older than 15.5.01.1 allows a local attacker to potentially obtain an access token. If the attacker succeeds, the token could be used to impersonate the account holder or access protected resources. The weakness conforms to open‑redirection problems in web applications, identified as CWE‑601.
Affected Systems
Samsung mobile devices running Samsung Account firmware prior to version 15.5.01.1 are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity risk, while the EPSS score is below 1%, suggesting a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local attacker with access to the device; no specific elevated privileges are mentioned in the description.
OpenCVE Enrichment