Samsung Smart Switch Insufficient Randomness in Key Generation Vulnerability Allowing Data Access

Vulnerability

A vulnerability exists in Samsung Smart Switch applications prior to version 3.7.68.6, where an insufficiently random secretKey allows adjacent attackers to access backup data from applications. This issue arises from improper key generation, creating a predictable key that could be exploited to retrieve sensitive data.

Impact

Exploitation of this vulnerability could lead to unauthorized access to backup data from applications, potentially exposing sensitive user information.

Remediation

Users can update to Samsung Smart Switch version 3.7.68.6 or later to address this vulnerability.

Added: Nov 5, 2025, 6:17 AM
Updated: Nov 5, 2025, 6:17 AM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.