Impact
The vulnerability resides in the handler for Samsung Mobile's My Galaxy custom URL scheme. Improper authorization permits a remote attacker to invoke this scheme and obtain sensitive information that should otherwise be protected. As a result, the attacker can read data that the user is not permitted to access, potentially compromising privacy and confidentiality. The weakness corresponds to improper authorization controls.
Affected Systems
Samsung Mobile: My Galaxy devices running versions earlier than 6.3. The advisory does not list specific firmware revisions, so any device with a firmware version below 6.3 is considered vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. No EPSS score is available, so the likelihood of exploitation remains unclear, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is likely to involve an attacker triggering the custom URL scheme locally or via a malicious application or web page that invokes the URL. With no confirmed exploitation evidence, the overall risk is moderate pending further monitoring.
OpenCVE Enrichment