Impact
Samsung DeX suffers from an improper access control flaw that enables an attacker who can physically reach the device to view the contents of notifications that are intended to be hidden. Because the flaw gives unauthorized visibility into user data, the attack results in the disclosure of potentially sensitive information.
Affected Systems
All Samsung mobile devices running Samsung DeX versions that were released before the SMR Apr‑2026 Release 1 update are vulnerable. Devices using earlier releases of DeX are therefore at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 4.7, placing it in the moderate range. No EPSS score is available, and it is not listed in the CISA KEV catalog. The flaw requires physical proximity to the device, meaning an attacker must be present near the device to exploit it. The limited impact and lack of remote exploitation reduce the overall risk, but exposure of private notification content still warrants prompt remediation.
OpenCVE Enrichment