Samsung ClipboardService Insufficient Permission Vulnerability Allowing Cross-User Image File Access

Vulnerability

A vulnerability exists in the ClipboardService component of Samsung devices, specifically in versions prior to the SMR April 2025 Release 1. This vulnerability arises from improper handling of permissions, allowing local attackers to access image files across multiple user accounts. Exploitation of this issue requires user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized access to image files across different user accounts on the device.

Remediation

Users can apply the SMR April 2025 Release 1 update to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.