Impact
Valid Smart Switch wallets before version 3.7.72.6 write passwords, account numbers and other sensitive material to a local file in plain text. An attacker with adjacent access to the device can read this file, gaining the stored values. The primary consequence is loss of confidentiality for the affected data.
Affected Systems
The flaw affects Samsung Mobile’s Smart Switch application on all operating systems where the product version is older than 3.7.72.6. No other Samsung Mobile products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate security risk, and the EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or physically adjacent; an attacker would need access to the device or nearby environment to read the stored files. Because the data is stored in cleartext, a successful read results in direct disclosure of highly sensitive information and represents a straightforward exploitation path once local access is achieved.
OpenCVE Enrichment