Impact
Samsung Notes contains an out-of-bounds write in versions prior to 4.4.45.5 that allows a local attacker to write beyond the bounds of a buffer, resulting in memory corruption. This corruption can undermine the integrity of application data and may affect the reliability and availability of the Notes app.
Affected Systems
The flaw affects all Samsung Notes installations on Samsung Mobile devices running a version earlier than 4.4.45.5, including the standard Notes app.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact and moderate exploitation complexity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation campaigns as of the latest data. Based on the description, it is inferred that the attack vector is local, requiring the attacker to have access to the device or to trick a user into interacting with malicious content in the Notes application.
OpenCVE Enrichment