Impact
The vulnerability arises from an improper authorization check in the ProxyHandler component of Samsung Mobile Devices. Local attackers can exploit this flaw to read the device’s proxy configuration settings. Access to these settings enables an attacker to learn network routing information, potentially redirect traffic, or inject malicious proxies, compromising data confidentiality and integrity.
Affected Systems
Samsung Mobile Devices prior to the SMR Aug‑2026 Release 1 firmware update are affected. The issue does not target specific models, but any device running a firmware version before this release can be impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score is 0.00106, which shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation. The flaw is exploitable only by users with local access to the device; therefore, the risk is confined to compromised local accounts. An attacker with local access could read proxy settings and potentially pivot to further network attacks if additional weaknesses exist.
OpenCVE Enrichment