Impact
Improper access control in the SettingsProvider before the SMR Sep‑2026 Release 1 enables a local attacker—one with physical or local user access—to read protected configuration data. The flaw stems from a missing or insufficient authorization check, compromising the confidentiality of sensitive information stored by the provider while offering no code execution or system‑wide control.
Affected Systems
The vulnerability affects Samsung Mobile Devices running firmware released prior to the SMR Sep‑2026 Release 1. Based on the description, it is inferred that any device with a pre‑release firmware version includes the flawed SettingsProvider. No specific device models or operating‑system versions are listed beyond the release date, implying a broad impact within the affected firmware generation.
Risk and Exploitability
The CVSS score of 5.1 rates the flaw as medium severity. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation, and the issue is not in the CISA KEV catalog. The attack vector is local; a malicious actor must be physically present or otherwise have local user privileges. Once the flaw is leveraged, the attacker can obtain confidential configuration data but cannot execute arbitrary code or gain broader system control. These conclusions about attack vector and affected firmware are inferred from the CVE description.
OpenCVE Enrichment