Description
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Valid Smart Switch wallets before version 3.7.72.6 write passwords, account numbers and other sensitive material to a local file in plain text. An attacker with adjacent access to the device can read this file, gaining the stored values. The primary consequence is loss of confidentiality for the affected data.

Affected Systems

The flaw affects Samsung Mobile’s Smart Switch application on all operating systems where the product version is older than 3.7.72.6. No other Samsung Mobile products or versions are listed as impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate security risk, and the EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or physically adjacent; an attacker would need access to the device or nearby environment to read the stored files. Because the data is stored in cleartext, a successful read results in direct disclosure of highly sensitive information and represents a straightforward exploitation path once local access is achieved.

Generated by OpenCVE AI on August 10, 2026 at 09:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Mobile Smart Switch to version 3.7.72.6 or later
  • Delete any stored credentials or sensitive data and confirm they are removed or re‑encrypted after the upgrade
  • Enable device‑wide encryption for additional protection
  • If the application is not essential, uninstall Smart Switch as a temporary countermeasure

Generated by OpenCVE AI on August 10, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:samsung:smart_switch:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung smart Switch
Vendors & Products Samsung
Samsung smart Switch

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Sensitive Information in Samsung Smart Switch
Weaknesses CWE-200
CWE-312

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Smart Switch
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:31:12.039Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21080

cve-icon Vulnrichment

Updated: 2026-08-10T17:29:00.555Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-10T09:17:21.677

Modified: 2026-08-19T16:31:24.293

Link: CVE-2026-21080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-312

    Cleartext Storage of Sensitive Information