Impact
Improper privileged attacker to launch arbitrary activities. The flaw bypasses normal authentication checks, enabling the attacker to specify and start any activity within the device, potentially executing malicious code or accessing sensitive data. This represents a local privilege escalation that can compromise confidentiality, integrity, or availability depending on the chosen activity.
Affected Systems
Samsung Mobile Devices running firmware older than the SMR Sep-2026 Release 1 update are affected. Devices that have not applied the September 2026 security update remain vulnerable.
Risk and Exploitability
The CVSS score of 4.6 classifies this vulnerability as moderate, and it is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low probability of exploitation. The attack requires local privileged access, so an attacker would need to already possess such. Once the vulnerability is exploited, the attacker can launch arbitrary activities, potentially leading to further escalation or damage.
OpenCVE Enrichment