Impact
The vulnerability is an improper access control flaw in the Link to Windows feature of Samsung Mobile Devices that permits a local attacker to open a connection with a paired PC without the user’s explicit permission or interaction. This unauthorized connection can potentially expose system resources or allow further exploitation, leading to compromised confidentiality, integrity, or availability of the PC.
Affected Systems
Samsung Mobile Devices that run the Link to Windows functionality prior to the SMR Sep-2026 Release 1 update. Any Samsung smartphone or tablet device that supports and has enabled Link to Windows, and its associated PC when the device is paired, is affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. EPSS is not available, and the vulnerability is not currently listed in the CISA KEV catalogue, suggesting it has not yet been widely exploited. The flaw is exploitable by a local attacker who has physical or network access to the Samsung device. The attacker would not need user interaction to establish the PC connection, implying that the attack could be carried out blindly after pairing. Remediation is most effective by updating to the patched SMR release, as no built‑in workaround is documented.
OpenCVE Enrichment