Executive brief
Samsung Health is a mobile application used for tracking fitness, nutrition, and sleep data. A security flaw in versions prior to 7.00.0.107 could allow a malicious app installed on the same device to access information about connected hardware, such as smartwatches or fitness trackers. This could lead to the unauthorized disclosure of device identifiers and connection details.
Technical details
An improper authorization vulnerability exists in the Samsung Health application due to insufficient access controls on internal components. A local attacker with low privileges (such as a malicious third-party application) can exploit this flaw to bypass intended restrictions and retrieve information regarding devices connected to the application. The vulnerability is rooted in the improper export or protection of application components, which fails to verify the authorization of the requesting process. Samsung has addressed this in version 7.00.0.107 by implementing proper access control checks.
Affected products
- Samsung Mobile Samsung Health prior to 7.00.0.107
Timeline
- 2026-07-07: advisory: Samsung Bulletin published
- 2026-07-10: disclosed: NVD publication date