Impact
The vulnerability is an improper access control flaw in Samsung Mobile’s Collection application. The flaw exists in all versions prior to 1.0.1.14 on Android 15 and 2.0.02.7 on Android 16. A local attacker can read sensitive data exposed by the app, leading to potential information disclosure. This weakness corresponds to unauthorized access to resources and can allow leakage of private information such as user data, session tokens, or configuration settings.
Affected Systems
Affected systems are Samsung devices running the Collection service with a version older than 1.0.1.14 on Android 15 or older than 2.0.02.7 on Android 16. The issue affects the smartphone vendor’s Collection app and all Android 15 and 16 devices that have not yet applied the patch. No other vendors or OS versions are listed.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity impact, and the presence of a local attack vector limits exploitation to an attacker with physical or local device access. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting that widespread exploitation has not been observed yet. However, the lack of a remote attack vector means an attacker must already have local access, which is still a significant risk for insider or compromised device scenarios. The weakness is a classic improper access control scenario, and remediation should focus on upgrading the app and locking down local access.
OpenCVE Enrichment