Impact
Improper export of Android application components in SamsungPassAutofill allows local attackers, with user interaction, to read sensitive data stored or managed by the app. The flaw is a classic information exposure weakness where components are mistakenly exposed to other applications. The potential impact is the leakage of confidential data such as passwords, personal identification, or other proprietary information accessible within the app's storage.
Affected Systems
Samsung Mobile’s SamsungPassAutofill application, versions prior to 5.2.10.x, is affected by the component export flaw. Any installation of 5.2.9.x or earlier may permit the locally triggered vulnerability.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires local user interaction and the presence of the vulnerable app; thus the threat is constrained to physically compromised or captive device scenarios.
OpenCVE Enrichment