Impact
The vulnerability is an incorrect authorization in Samsung Health before version 7.0.0. This flaw permits any local attacker with access to the device to bypass authorization controls and read protected health data stored by the app, resulting in a confidentiality breach.
Affected Systems
Samsung Mobile Samsung Health applications installed on Android devices running any version earlier than 7.0.0. The flaw is present in all pre‑7.0.0 builds as indicated by the vendor information. No specific device models are listed; all Samsung Health users with older versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. The attack requires local possession of the device; an attacker could invoke the app’s functions or inject malicious code into the device to read data. Because the flaw is limited to local execution, the risk is confined to the device owner or anyone with physical/local access, but the sensitive nature of the data makes it a significant concern.
OpenCVE Enrichment