Impact
The vulnerability is an improper export of Android application components in Samsung Mobile Bixby Touch prior to version 4.3.01.17. This flaw enables local attackers to read sensitive data that should have been protected by the component boundaries. Because the components are exposed, confidential information such as personal settings or usage data can be accessed without authorization. The weakness relates to the misuse of component visibility, resulting in an information disclosure.
Affected Systems
Affected vendor is Samsung Mobile and product Bixby Touch. All releases before version 4.3.01.17 are compromised. Devices that run any earlier build of Bixby Touch on Android are impacted.
Risk and Exploitability
The CVSS score is 6.9, reflecting medium severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need local device access; the flaw is exploitible through the exported components, meaning the attacker can trigger the exposure by executing code within the app or using the exposed component path. The attack surface is limited to compromised or shared devices, but the risk remains notable for any device where local adversaries can operate.
OpenCVE Enrichment