Impact
The flaw arises from the inclusion of sensitive data in the camera driver’s debugging code within Samsung Exynos processors. When debug output is accessed, confidential information that should remain protected can be exposed, resulting in an information leak. The weakness is an improper handling of confidential data in code that is visible to a debugging interface, identified as CWE-215.
Affected Systems
Samsung Exynos 1330 firmware and its variants—including the 1380, 1480, 2400, 1580, 2500, 2600, and 1680—are affected. The issue resides specifically in the camera driver component of these mobile processors.
Risk and Exploitability
With a CVSS score of 2.8, the vulnerability is classified as low severity. The EPSS score is below 1%, indicating a very low likelihood of exploitation. It is not listed in the CISA KEV catalog, and no public exploit is known. The attack vector is inferred to be local; an adversary would need physical or software access that allows them to read the device’s debugging output, which is normally restricted to developers or system software.
OpenCVE Enrichment