CVE-2026-21097

Summary

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Affected Software

VendorProductVersion RangeStatus
Samsung MobileSamsung Mobile DevicesSMR Sep-2026 Release in Android 14,15,16,17 < *unaffected

Weaknesses

  • CWE-285: Improper Authorization

References