VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18680

CVE-2017-18680

Description

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interface allows Add User actions, leading to an unintended ability to access user data in external storage. The Samsung ID is SVE-2016-7797 (March 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

On Samsung tablets with Android L(5.0/5.1) and M(6.0), the lockscreen Add User feature allows unauthorized access to external storage data.

Vulnerability

The lockscreen interface on Samsung mobile devices running Android L (5.0/5.1) and M (6.0) for tablets exposes the Add User action. This action should be restricted when the device is locked, but it remains accessible, allowing an unintended ability to access user data stored on external storage. The affected versions are L(5.0/5.1) and M(6.0) tablets.

Exploitation

An attacker with physical access to the device can use the lockscreen Add User feature to create a new user account. Once the new user is created, they can navigate to external storage (e.g., an SD card) and access data belonging to the original user. No authentication or additional privileges are required beyond the lockscreen access.

Impact

Successful exploitation results in unauthorized disclosure of user data stored on external storage. The attacker gains read access to files that may include personal information, media, or other sensitive content. The compromise is limited to external storage; internal storage remains protected by the lockscreen.

Mitigation

Samsung addressed this issue in a security update released in March 2017, identified by SVE-2016-7797. Users should update their devices to the latest firmware to receive the fix. No workarounds are documented for unpatched devices.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.