Impact
Improper input validation in Samsung Email versions older than 6.2.13.1 allows an attacker to specify file names or paths that the application will accept for file creation. The flaw enables the creation of arbitrary files entirely within the Email app sandbox, potentially allowing modification of existing files or insertion of new ones. This can compromise the confidentiality, integrity, or availability of the app’s internal state by altering configuration files, inserting malicious payloads, or corrupting data stored by the application.
Affected Systems
Samsung Mobile devices running Samsung Email versions earlier than 6.2.13.1 are affected. The vulnerability resides solely in the application code, not the underlying operating system or device hardware.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity issue, and the EPSS score of less than 1% shows a low likelihood of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the device; the most likely scenario is that an attacker who has physical possession of or otherwise locally compromised the device can trigger the flaw.
OpenCVE Enrichment