Description
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Published: 2026-08-10
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper input validation in Samsung Mobile Smart Switch versions prior to 3.7.72.6, which enables attackers located adjacent to the device to read sensitive data stored on the device. This flaw can compromise the confidentiality of user data, exposing potentially personal or corporate information without affecting integrity or availability.

Affected Systems

Samsung Mobile Smart Switch products on mobile devices running firmware versions older than 3.7.72.6.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity level. With the EPSS score unavailable, the exploitation likelihood remains uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring proximity to the device as the description references adjacent attackers. An attacker could leverage this weakness to read sensitive data but would not gain remote code execution or broader system compromise.

Generated by OpenCVE AI on August 10, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Smart Switch to version 3.7.72.6 or later to incorporate the vendor's fix.
  • If an upgrade is not immediately possible, uninstall or disable Smart Switch to eliminate the risk surface.
  • Consult Samsung’s security bulletin for additional advisory information and apply any future security updates as they become available.

Generated by OpenCVE AI on August 10, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-200

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:45:40.902Z

Reserved: 2025-12-11T01:33:35.826Z

Link: CVE-2026-21083

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor