Impact
Path traversal in the ImsService component of Samsung Mobile Devices allows a remote attacker to write supplying a crafted file path the attacker can create permissions, potentially leading to persistent malicious content or further privileged actions if the images are later processed by system services.
Affected Systems
Samsung Mobile Devices. The vulnerability exists in the ImsService implementation prior to the SMR Sep-2026 Release 1, meaning any device running an older firmware revision is at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and the EPSS score of < 1% shows a very low, but non‑zero, likelihood of exploitation, while the KEV status indicates it is not listed. Despite the low EPSS, the vulnerability still poses a serious risk of to be remote, likely through a network interface exposed by the ImsService, as the description refers to remote attackers triggering the flaw.
OpenCVE Enrichment