CVE-2017-18648
Description
An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file read/write operations can occur in the locked state via a crafted MTP command. The Samsung ID is SVE-2017-10086 (November 2017).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Samsung mobile devices (KK to N) allow arbitrary file read/write in locked state via crafted MTP command, enabling data access without authentication.
Vulnerability
An issue exists in Samsung mobile devices running Android versions KK (4.4.x), L (5.x), M (6.x), and N (7.x) that allows arbitrary file read and write operations while the device is locked. The vulnerability is triggered via a crafted MTP (Media Transfer Protocol) command. The Samsung ID for this issue is SVE-2017-10086, reported in November 2017.
Exploitation
An attacker with physical access to a locked device can send a specially crafted MTP command over USB. No authentication or user interaction is required beyond connecting the device to a computer. The attacker does not need to unlock the screen or bypass the lock screen.
Impact
Successful exploitation allows the attacker to read and write arbitrary files on the device's filesystem, including sensitive user data such as contacts, messages, photos, and application data. This compromises the confidentiality and integrity of all data stored on the device, bypassing the lock screen protection.
Mitigation
Samsung has not publicly disclosed a specific patch for this vulnerability in the available references. Users should ensure their devices are updated to the latest firmware version provided by Samsung. As of the publication date (April 2020), no workaround or fix details are available from the referenced source.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Samsung/mobile devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- security.samsungmobile.com/securityUpdate.smsbmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.