Impact
Improper input validation in Samsung Dialer allows remote attackers to access SIM‑related functions. The flaw can be triggered when a user interacts with a malicious interface, enabling the attacker to read or manipulate SIM data. The weakness is classified as improper input validation, which can expose sensitive information and provide control over SIM services.
Affected Systems
All Samsung Mobile Devices running the Samsung Dialer prior to the SMR Aug‑2026 Release 1 are susceptible. The vulnerability applies to devices that have not yet installed the August 2026 firmware update.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity. Because a user interaction is required and no public exploit is currently documented, the likelihood of exploitation is moderate. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that it has not been widely exploited in the wild yet.
OpenCVE Enrichment