Executive brief
Samsung Email, a mobile application for managing email accounts on Samsung devices, contains a vulnerability that allows a local attacker to create unauthorized files. This occurs within the application's private storage area (sandbox), which could potentially lead to data corruption or unauthorized modification of application settings. Users should update to the latest version of the app to resolve this issue.
Technical details
A vulnerability classified as improper input validation exists in Samsung Email before version 6.2.13.1. A local attacker can exploit this flaw to create arbitrary files within the application's sandbox environment. The attack vector is local, requiring the attacker to have some level of access to the device, though no specific privileges or user interaction are noted as prerequisites. The vulnerability has been addressed in version 6.2.13.1 by implementing stricter input validation checks. The vendor assigned a CVSS 4.0 score of 5.1.
Affected products
- Samsung Mobile Samsung Email prior to 6.2.13.1
Timeline
- 2026-07-07: advisory: Samsung Mobile Bulletin published
- 2026-07-10: disclosed: NVD publication date