Description
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
Published: 2026-08-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the handler for Samsung Mobile's My Galaxy custom URL scheme. Improper authorization permits a remote attacker to invoke this scheme and obtain sensitive information that should otherwise be protected. As a result, the attacker can read data that the user is not permitted to access, potentially compromising privacy and confidentiality. The weakness corresponds to improper authorization controls.

Affected Systems

Samsung Mobile: My Galaxy devices running versions earlier than 6.3. The advisory does not list specific firmware revisions, so any device with a firmware version below 6.3 is considered vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is likely to involve an attacker triggering the custom URL scheme locally or via a malicious application or web page that invokes the URL. With no confirmed exploitation evidence, the overall risk is moderate pending further monitoring.

Generated by OpenCVE AI on August 10, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to My Galaxy firmware version 6.3 or later to eliminate the flaw.
  • If an update is not available, disable or restrict the use of the custom URL scheme by changing app permissions or applying device‑management policies.
  • Continuously monitor system logs for unauthorized activity involving the URL scheme and be ready to respond if misuse is detected.

Generated by OpenCVE AI on August 10, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile my Galaxy
Vendors & Products Samsung Mobile
Samsung Mobile my Galaxy

Mon, 10 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in My Galaxy URL Scheme Enables Sensitive Data Access

Mon, 10 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Custom URL Scheme Handler Allows Remote Access to Sensitive Information
Weaknesses CWE-284

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-939
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Custom URL Scheme Handler Allows Remote Access to Sensitive Information
Weaknesses CWE-284

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile My Galaxy
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:16:27.565Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21075

cve-icon Vulnrichment

Updated: 2026-08-10T17:16:10.459Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T09:17:21.023

Modified: 2026-08-18T15:04:46.610

Link: CVE-2026-21075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:26:01Z

Weaknesses
  • CWE-939

    Improper Authorization in Handler for Custom URL Scheme