Impact
Improper input validation in Samsung Contacts before the SMR Aug‑2026 Release 1 allows a physical attacker to read contact data belonging to other user profiles on the device, violating user confidentiality. The flaw is a classic example of insufficient validation that permits cross‑profile data leakage without authorization.
Affected Systems
Samsung Mobile Devices running Samsung Contacts prior to the 2026 Aug release are affected. The vulnerability was present in all builds of the Contacts application shipped before the SMR Aug‑2026 Release 1 update, regardless of specific firmware version.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The attack requires a physical attacker to interact with the device, making it an in‑physical‑threat scenario. Current defenders should assume that unauthorized access is possible until devices are updated to the patched release.
OpenCVE Enrichment