Impact
A path traversal flaw exists in the SemClipboardService component of Samsung Mobile firmware, allowing a local user to craft requests that resolve to arbitrary file paths. By exploiting this weakness, an attacker can read or modify files normally protected with system privileges, compromising data confidentiality and integrity. The vulnerability does not grant remote code execution directly but can be leveraged to elevate privileges further if additional weaknesses exist.
Affected Systems
Samsung Mobile Devices running firmware versions prior to SMR Jul‑2026 Release 1, which include the unpatched SemClipboardService, are affected.
Risk and Exploitability
The CVSS score of 6.8 denotes moderate severity, and the EPSS score of < 1 % together with the lack of listing in CISA’s KEV catalog indicate that exploitation is not currently widespread. The attack vector is local; an adversary must have user‑level access to trigger the path traversal. The narrow exploitation window and absence of network reachability reduce the overall risk of immediate compromise.
OpenCVE Enrichment