Impact
The vulnerability is a use‑after‑free flaw in the DualDAR component of Samsung Mobile Devices. It allows a local attacker with privileged access to execute arbitrary code with root privileges, giving complete control over the device, including the ability to read, modify, or delete any data and install additional malware. The weakness is represented by CWE‑416.
Affected Systems
The affected product is Samsung Mobile Devices, specifically the DualDAR component. No specific firmware or software version range is listed in the available data.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, but the lack of publicly known exploits and the need for local privileged access suggest that exploitation is unlikely unless a device is already compromised. The vulnerability is listed as not in the CISA KEV catalog, so no public exploits are currently known. The likely attack vector involves a local attacker who already has some privileged execution on the device, such as through a malicious application or an existing system compromise, leveraging memory corruption to gain root privileges.
OpenCVE Enrichment