Impact
The vulnerability in Samsung Account prior to version 15.5.01.1 permits a remote attacker to trigger a URL redirection that may capture the account’s access token. This can enable the attacker to impersonate the user or gain unauthorized access to protected resources. The weakness conforms to the open‑redirection problem observed in web applications.
Affected Systems
Samsung mobile devices running Samsung Account before v15.5.01.1 are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The severity score of 7 indicates high risk, but the likelihood of exploitation is below 1% and the vulnerability is not listed in the known exploited vulnerabilities catalog. Remote exploitation is inferred, likely over the network, and does not require elevated local privileges. If an attacker controls the redirect target, credential theft is possible.
OpenCVE Enrichment