Impact
The flaw involves an incorrect privilege assignment in the Bluetooth subsystem when a Samsung Mobile device is in Maintenance mode. An attacker who is physically near the device can exploit this to elevate privileges, bypassing the Extend Unlock security feature. The resulting privilege escalation could allow unauthorized modification of device settings or access to protected functionality.
Affected Systems
Affected devices are Samsung Mobile Devices running firmware versions prior to the SMR Apr‑2026 Release 1 update. Devices that have not applied the latest firmware and still operate in the earlier Maintenance mode remain vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity vulnerability, and the lack of an EPSS score or KEV listing suggests lower likelihood of widespread exploitation. Based on the description, it is inferred that the attack vector requires physical proximity to the device’s Bluetooth interface. Remediation requires installing the SMR Apr‑2026 Release 1 firmware; until then, disabling Bluetooth or restricting Maintenance mode can reduce exposure. No public exploit is known.
OpenCVE Enrichment