Impact
Samsung mobile devices contain an input‑validation flaw in Retail Mode that enables a local user to invoke privileged functions that should be restricted. The flaw bypasses the normal authorization checks and can be triggered by locally crafted input. This allows a user who can interact with the device to gain elevated privileges on the system, potentially granting full control over the device's operating system and data.
Affected Systems
All Samsung Mobile Devices running Android 14.0, 15.0 or 16.0 are affected when the system maintains any System Maintenance Release (SMR) issued prior to the April 2026 Release 1 update. Each of the numerous monthly SMRs for Android 14 by 16 listed in the Common Platform Enumeration data is vulnerable, as the issue exists in the baseline Retail Mode implementation before the April 2026 patch.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 6.6 and an EPSS score below 1 %, indicating a moderate severity but a low likelihood of widespread exploitation. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires physical or otherwise authorized access to the device, making the attack vector local. While the exploit probability is low, any successful privilege escalation can serve as a foothold for further attacks, so the risk remains significant for end‑users who rely on Retail Mode.
OpenCVE Enrichment