Impact
An improper access control flaw (CWE‑284) in SamsungSEAgentService allows a local attacker to retrieve sensitive information, resulting in information disclosure (CWE‑200). The vulnerability is limited to local execution on the device and does not require remote code execution or network connectivity. If successfully exploited, an attacker who can physically access the device or has privileged local access could read confidential data managed by the SE Agent service, compromising user privacy and device integrity.
Affected Systems
Samsung Mobile Devices that run SamsungSEAgentService versions prior to the SMR Jul-2026 Release 1 update. No specific patch version numbers are listed, and the vendor has not supplied further version details in this advisory.
Risk and Exploitability
The moderate CVSS score of 6.9 indicates a significant security impact, but the EPSS score of < 1 % suggests a very low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV. The flaw requires physical or local administrative access, so an attacker would need to own or have a privileged user on the device to leverage it. Because the flaw exposes sensitive information, it remains a significant risk for devices that have not yet been updated to the July 2026 release.
OpenCVE Enrichment