Impact
Improper validation of user-supplied data within Samsung Tips permits a local attacker to launch an arbitrary activity with the app’s privilege level. The vulnerability is triggered only after the user interacts with the application, allowing a malicious payload to be delivered through crafted input. The impact is the execution of privileged operations not intended by the app, potentially exposing sensitive data or enabling further privilege escalation.
Affected Systems
Android devices running versions prior to 17 with Samsung Tips installed. Any device that has the app installed and has not yet been updated to a version that addresses the input validation flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack requires local, user interaction to trigger the flaw, limiting the realistic exploitation potential. Nonetheless, the ability to launch arbitrary activities with elevated privilege warrants timely remediation.
OpenCVE Enrichment