Impact
The vulnerability arises when Samsung Contacts improperly exports Android application components, allowing a local attacker to delete a file using the app’s privileges. This flaw corresponds to CWE-926 and can compromise data integrity by removing files that should have been protected under normal application permissions.
Affected Systems
Samsung mobile devices that run versions of Samsung Contacts prior to the SMR Aug‑2026 Release 1 update are impacted. The issue is limited to the Contacts application bundled with Samsung’s mobile platform; other applications are not directly affected.
Risk and Exploitability
The CVSS score of 6.9 labels the flaw as moderate. EPSS is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of exploitation. The attack vector is inferred to be local – an attacker must have physical or local software access to trigger the exported component. If enabled, the attacker could delete files within the scope of the Contacts app’s privileges, potentially removing important data.
OpenCVE Enrichment