Impact
Improper verification of intent by a broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows a local attacker to disable enhanced data protection settings. The vulnerability results from an insufficient check of the broadcast’s origin and leads to a decrease in confidentiality protection for user data handled by the assistant. It does not allow code execution or remote compromise but removes a layer of security safeguards established by the application.
Affected Systems
Samsung Mobile devices with the Samsung Cloud Assistant component before version 9.0.5 are affected. The issue is tied to the broadcast receiver that controls data protection settings within the service.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS score of 0.00111 indicates a very low exploitation probability, and the vulnerability is not yet listed in the KEV catalog. The flaw can be exploited locally by any application that can send an Intent to the receiver; no network or privileged access is required beyond local execution. Because the likelihood of exploitation is mild, but once active, it immediately diminishes data protection guarantees.
OpenCVE Enrichment