CVE-2026-21059

Summary

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

Affected Software

VendorProductVersion RangeStatus
Samsung MobileSamsung Mobile DevicesSMR Aug-2026 Release in Android 16 < *unaffected

Weaknesses

  • CWE-926 Improper export of android application components

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References