Impact
A path traversal flaw exists in the Wallpaper service of Samsung Mobile Devices. It allows a local attacker with privileged access to read arbitrary files on the device with system server privileges, exposing sensitive data and enabling further abuse. The weakness corresponds to CWE-22 (Path Traversal) and CWE-285 (Privilege Management).
Affected Systems
Samsung Mobile Devices running firmware versions prior to SMR Jul-2026 Release 1 are affected. No specific sub-product or version list was provided.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The attacker must be local and already hold privileged access; however, the flaw permits escalation to system server privilege, a critical capability. The EPSS score of < 1% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation.
OpenCVE Enrichment