Impact
An improper input validation flaw in Samsung Contacts allows a local attacker to delete arbitrary files that the Contacts app can access. The vulnerability can lead to loss of contact data, application malfunction, or broader system instability if critical files are removed. It represents an internal misuse of application privileges rather than a denial‑of‑service or data‑exfiltration issue, but the potential for damaging device state warrants notice.
Affected Systems
All Samsung Mobile Devices running Samsung Contacts versions preceding the SMR Aug‑2026 Release 1 are affected. No specific build numbers are listed, but any device that has not yet installed the August 2026 service release is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers must obtain local device access to exploit the flaw, which limits the overall threat exposure to individuals with physical or remote but privileged access to the device.
OpenCVE Enrichment