Impact
The vulnerability in SecTelephonyProvider arises from improper handling of insufficient privileges, allowing a local attacker to bypass protection checks and read privileged system files. This flaw does not require network access or remote exploitation; the attacker must have physical or local access to the device to trigger the attack. Successful exploitation results in unauthorized access to sensitive data, potentially compromising the confidentiality and integrity of the device.
Affected Systems
All Samsung Mobile Devices running firmware versions prior to the SMR Jun-2026 Release 1 are affected. The flaw resides in the SecTelephonyProvider component of the Android telephony framework across Android 14, 15 and 16 revisions listed in the CPE data.
Risk and Exploitability
With a CVSS score of 4.6 the vulnerability presents moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog, further supporting a low likelihood of widespread exploitation. The attack vector is local device access; therefore an attacker needs physical presence or local execution privileges to exploit the flaw.
OpenCVE Enrichment