Impact
Device Care performs an improper check for exceptional conditions before the SMR Apr‑2026 release. This flaw allows a physical attacker to bypass Knox Guard protection, exposing the device to unauthorized access and potential theft of data. The weakness is a failure to validate guard conditions properly.
Affected Systems
Affected Samsung mobile devices include all models running Android 14.0, 15.0, or 16.0 that have not yet applied the SMR Apr‑2026 Release 1 update. The list of impacted firmware builds covers SMR releases from 2022 through 2026 for these Android versions, as shown in the provided CPE strings.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, and the EPSS score is below 1 percent, suggesting low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires physical possession of the device, implying that only attackers with direct device access can benefit, yet the impact of bypassing Knox Guard would be significant for both confidentiality and integrity.
OpenCVE Enrichment