Impact
The flaw involves incorrect privilege assignment in the Bluetooth stack when the device is in Maintenance mode prior to the April 2026 SMR Release 1 update. This weakness allows a physical attacker to gain privileges that bypass the Extend Unlock feature. The weakness is classified as CWE‑732, which deals with incorrect privilege assignment.
Affected Systems
The issue affects Samsung Mobile Devices running Android 14, 15, and 16 that have not yet received the April 2026 SMR Release 1 update. The vulnerability manifests in any SMR release before that date: versions ranging from smr‑jan 2022‑r1 to smr‑jan 2026‑r1 for Android 14, and analogous months for Android 15 and 16 up to the appropriate SMR releases.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate impact, and the EPSS score of less than 1 % suggests low likelihood of exploitation. However, the attack requires physical proximity and the device to be in Maintenance mode, making it a local attack. The vulnerability is not listed in the KEV catalog. Until a patch is applied, physical attackers could bypass Extend Unlock and potentially gain further privileges.
OpenCVE Enrichment