Description
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization logic within Samsung Health that allows a local attacker to view personal health information. It is a classic improper authorization flaw, equivalent to CWE‑285, which can lead to exposure of confidential data such as medical records or personal metrics. The impact is the loss of confidentiality for users who rely on the app to store or manage private health data.

Affected Systems

Samsung Health on Samsung Mobile devices running any version prior to 7.0.0 is affected. The issue is present in all releases before the 7.0.0 update, regardless of device model or Android version, as the authorization check is performed inside the app itself.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, reflecting that the flaw does not allow remote code execution but can subvert data privacy. No EPSS score is available, but the absence of a KEV listing suggests it has not yet been widely exploited. The attack vector is local; an attacker must have physical or device-access privileges, such as a renter or someone with temporary access to a device. Once local access is achieved, the authorization bypass exposes private health data to the attacker.

Generated by OpenCVE AI on August 10, 2026 at 09:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Health to version 7.0.0 or newer, which includes the fixed authorization logic.
  • If an upgrade is not immediately possible, restrict the app's permissions to prevent local data access or use device-level restrictions (e.g., device administration or parental controls) to limit physical access.
  • Consider disabling or limiting sharing features within the app until the patch is applied to reduce the risk of data exposure to other apps or services.
  • Monitor device security logs for unusual activity that could indicate a local data extraction attempt.

Generated by OpenCVE AI on August 10, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health App
First Time appeared Samsung Mobile
Samsung Mobile samsung Health
Weaknesses CWE-285
Vendors & Products Samsung Mobile
Samsung Mobile samsung Health

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Health
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:42:54.080Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21076

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:30:03Z

Weaknesses