Impact
Improper access control in the IAFDService component of Samsung Mobile Devices prior to the SMR Jul‑2026 Release 1 allows local privileged attackers to invoke privileged APIs. This flaw enables any process or user with local privilege to misuse these APIs, potentially allowing unauthorized actions that could affect the device’s operating system or applications.
Affected Systems
Samsung Mobile Devices operating with firmware released before the SMR Jul‑2026 Release 1 are affected. All devices running versions older than this update inherit the vulnerability in the IAFDService component.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local privileged access to exploit this flaw, limiting the threat to environments where local users can gain or already possess elevated privileges. The overall risk remains moderate, but patching is advised to prevent potential misuse of the privileged APIs.
OpenCVE Enrichment