Impact
Samsung Health versions earlier than authorization flaw that permits a local attacker to access‑control issue (CWE‑284) that bypasses checks normally required to restrict data access. The result is unauthorized disclosure of device data that could include health metrics, identifiers, or usage statistics.
Affected Systems
Samsung Health for Android, sold by Samsung Mobile. All installations of the app before version 7.00.0.107 are affected and local access.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate severity. With an EPSS score of less than 1%, the probability of exploitation in the wild is very low. The vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale active exploitation. Likely attackers are those with local device access who or physically tamper with the device. No remote exploitation path or privilege escalation is documented.
OpenCVE Enrichment