Impact
An improper access control flaw in SamsungSEAgentService allows a local attacker to retrieve sensitive information, resulting in an information disclosure vulnerability. The flaw permits reading data that the SE Agent service protects, potentially exposing personal or device‑specific data. The impact is confined to confidentiality; there is no mention of integrity or availability compromise.
Affected Systems
Samsung Mobile Devices that have not applied the Samsung Mobile security update released in July 2026, which contains an updated SE Agent Service. No specific patch or version numbers are listed beyond the update month, so any device running the pre‑July 2026 release of SamsungSEAgentService is vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate level of severity, while the EPSS score of < 1 % signals a very low probability of exploitation currently. The vulnerability requires local access and does not involve remote code execution or network exploitation; therefore physical or privileged local access is needed. Because the flaw leads to sensitive data exposure and is not listed in CISA KEV, affected devices should update promptly, though the risk of widespread exploitation remains low at present.
OpenCVE Enrichment