Description
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Valid Smart Switch wallets before version 3.7.72.6 write passwords, account numbers and other sensitive material to a local file in plain text. An attacker with adjacent access to the device can read this file, gaining the stored values. The primary consequence is loss of confidentiality for the affected data.

Affected Systems

The flaw affects Samsung Mobile’s Smart Switch application on all operating systems where the product version is older than 3.7.72.6. No other Samsung Mobile products or versions are listed as impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate security risk, and the EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or physically adjacent; an attacker would need access to the device or nearby environment to read the stored files. Because the data is stored in cleartext, a successful read results in direct disclosure of highly sensitive information and represents a straightforward exploitation path once local access is achieved.

Generated by OpenCVE AI on August 10, 2026 at 09:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Mobile Smart Switch to version 3.7.72.6 or later
  • Delete any stored credentials or sensitive data and confirm they are removed or re‑encrypted after the upgrade
  • Enable device‑wide encryption for additional protection
  • If the application is not essential, uninstall Smart Switch as a temporary countermeasure

Generated by OpenCVE AI on August 10, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Sensitive Information in Samsung Smart Switch
Weaknesses CWE-200
CWE-312

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:43:38.818Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21080

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-312

    Cleartext Storage of Sensitive Information