Impact
Improper access control in the SystemUI component of Samsung Mobile Devices, as disclosed prior to the Sep-2026 release, permits a local attacker to launch arbitrary activities. The flaw allows the attacker to request any activity through SystemUI without proper authorization checks, potentially enabling execution of malicious code, data exfiltration, or other non‑authorized functions. Because the activities run with the system's privileges, the impact includes full device compromise and loss of confidentiality, integrity, and availability for the affected device.
Affected Systems
Samsung Mobile Devices, specifically the SystemUI component. No specific firmware or release numbers are listed, but the vulnerability exists in versions prior to the Sep‑2026 release 1 of the Samsung Mobile Release (SMR).
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high severity vulnerability. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. The lack of remote execution constraints suggests that the attack vector is local, requiring the attacker to be present on the device or have local privileges. Exploitation would involve invoking a SystemUI activity with insufficient or missing access control checks. Given the medium‑high CVSS and the local nature of the vector, organizations should treat this as a potentially significant risk for devices that are not updated to the secure firmware release.
OpenCVE Enrichment