Impact
The flaw is an improper input validation in the Samsung Message application. This weakness can be exploited to read or trigger sensitive data through crafted input. The main consequence is information disclosure to a malicious actor who can manipulate the input.
Affected Systems
Samsung mobile devices running the Message app that have not yet applied the SMR Aug‑2026 Release 1 update are vulnerable. All models with the legacy Message component that still ship prior to that firmware release fall into this scope.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.1, indicating moderate severity. EPSS data is not available, and it is not listed in the CISA KEV catalog, suggesting no publicly known exploits. An attacker would need physical access to the device and would need to supply malicious input via the Message interface to trigger the disclosure. The lack of network or user level access limits remote proliferation.
OpenCVE Enrichment