Impact
Improper input validation in Samsung's Galaxy Themes software before the Aug‑2026 release allows an attacker who gains physical access to a device to trigger arbitrary activity execution. The flaw permits the malicious actor to craft an input that is not validated correctly by the theme component, leading to uncontrolled launch of an Android activity. Because the vulnerability can be exploited with direct physical interaction, it primarily threatens device integrity and potentially user privacy, depending on which activity is launched.
Affected Systems
The vulnerability affects Samsung Mobile Devices running Galaxy Themes prior to the SMR Aug‑2026 Release 1. Users of older firmware or unpatched theme packages are at risk.
Risk and Exploitability
The CVSS score of 5.2 indicates a medium severity and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is physical; an adversary must have physical proximity to the device to supply the malformed input. There are no publicly disclosed exploits or detailed attack scripts, but once physical access is achieved, the information flow control around the theme handler can be bypassed to launch any activity granted to the system. Due to the lack of remote exploitability, the immediate risk to most users is constrained to scenarios where an attacker can physically interact with the device.
OpenCVE Enrichment