Impact
The flaw is an authorization bypass in the SemClipboardService feature of Samsung Mobile Devices, letting a local attacker read clipboard data without proper permission checks. This vulnerability compromises the confidentiality of any information users copy to the clipboard, including personal, financial, or sensitive business data. The weakness is an improper access control error that directly exposes user data to local attackers within the device’s operating environment.
Affected Systems
Samsung Mobile Devices are impacted. No specific version numbers are provided, but the issue applies to any device running the SemClipboardService prior to the SMR Aug-2026 Release 1 update.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is currently not listed in CISA’s KEV catalog. The likely attack vector is local, requiring physical or close proximity access to the device. An attacker would need to be on the device or able to execute code with local privileges to exploit the service; no remote exploitation vector is described.
OpenCVE Enrichment