Impact
Samsung Mobile’s Weaver component contains an improper access control flaw that allows a local attacker to cause the device to become inoperable, effectively denying service. The weakness is a classic example of CWE‑284, improper access control, where unauthorized local users can exploit the vulnerability to disrupt device functionality.
Affected Systems
The vulnerability affects Samsung Mobile Devices running Weaver firmware prior to the SMR Aug‑2026 Release 1 update. All affected devices using earlier firmware versions are susceptible to this issue.
Risk and Exploitability
The CVSS score of 7 indicates high severity, while the EPSS score is not available, implying a moderate to low exploit probability under current data. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local physical or trusted access to the device to exploit this flaw, making it a local denial‑of‑service attack rather than a remote exploitation scenario.
OpenCVE Enrichment