Impact
The vulnerability is an incorrect authorization logic within Samsung Health that allows a local attacker to view personal health information. It is a classic improper authorization flaw, equivalent to CWE‑285, which can lead to exposure of confidential data such as medical records or personal metrics. The impact is the loss of confidentiality for users who rely on the app to store or manage private health data.
Affected Systems
Samsung Health on Samsung Mobile devices running any version prior to 7.0.0 is affected. The issue is present in all releases before the 7.0.0 update, regardless of device model or Android version, as the authorization check is performed inside the app itself.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, reflecting that the flaw does not allow remote code execution but can subvert data privacy. No EPSS score is available, but the absence of a KEV listing suggests it has not yet been widely exploited. The attack vector is local; an attacker must have physical or device-access privileges, such as a renter or someone with temporary access to a device. Once local access is achieved, the authorization bypass exposes private health data to the attacker.
OpenCVE Enrichment