Impact
Samsung Health prior to version 7.0.0 is vulnerable to a relative path traversal flaw, allowing an attacker who can execute code on the device to read files outside the intended application directory. This results in the disclosure of sensitive user information stored on the device, compromising confidentiality. The weakness is a classic path traversal issue.
Affected Systems
The affected product is Samsung Health on Samsung Mobile devices. Versions earlier than 7.0.0 are impacted; no specific patch release versions are listed beyond this threshold.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating a medium severity impact. EPSS data is not available, but the flaw requires local execution or access to the device, so remote exploitation is unlikely. It is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been reported yet. Nevertheless, once on a device an attacker can read arbitrary files, so the potential for data compromise remains significant.
OpenCVE Enrichment