Impact
The flaw allows a local attacker to read data considered confidential. The vulnerability is present in all builds released before SMR Jul‑2026 Release 1 on Samsung Mobile devices. Because the component can bypass normal authorization checks, an attacker can gain access to information such as user identifiers, configuration data, or credentials. Based on the description, it is inferred that the weakness corresponds to CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).
Affected Systems
Devices that run a SmartThingsKit firmware prior to SMR Jul-2026 Release 1 on Samsung Mobile devices are affected. The vendor does not specify which device models are included, so it is unclear whether the vulnerability spans all scope of the impact across device models is not provided in the available information.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, meaning exploitation is unlikely in the wild. The flaw requires local access, such as physical presence or control over the local network, for an attacker to exploit the vulnerability.
OpenCVE Enrichment