Impact
This vulnerability results from improper export of Android application components in Samsung Mobile's InputSharing application. An attacker with local access to a device can exploit the exposed components to read sharing data that is intended to remain private, leading actors to bypass component visibility restrictions and gain unauthorized data access.
Affected Systems
Samsung Mobile InputSharing affected. Devices running any version prior to 2.7.01.4 on Android are vulnerable. The issue is specific to the application bundled with Samsung Mobile devices.
Risk and Exploitability
The CVSS score of 6.9 represents moderate severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw requires local device access, an attacker who gains local access can read or exfiltrate sharing data via the exported components. No known public exploitation, and the impact is limited to information disclosure rather than code execution.
OpenCVE Enrichment