Description
Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.
Published: 2026-01-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

Improper access control in the Samsung Android SLocation service allows a local attacker to invoke privileged APIs that are normally restricted. The vulnerability is an instance of improper control over access to protected functionality, which can enable the attacker to perform actions such as reading sensitive data, modifying system settings, or otherwise compromising device integrity.

Affected Systems

Samsung Mobile Devices running Android 15.0 and 16.0 firmware builds before the SMR Jan-2026 Release 1 update are affected. The impacted builds include all monthly security rollups listed in the Common Platform Enumeration entries for Android 15.0 and Android 16.0, spanning from March 2025 through late 2025 and into early 2026.

Risk and Exploitability

The flaw is exploitable locally; an attacker must already have physical or logical access to the device to use it. The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of wild exploitation at present. The flaw is not listed in CISA KEV, suggesting no large‑scale exploitation is known. The attack vector is local access, inferred from the description which states "local attackers" can execute privileged APIs.

Generated by OpenCVE AI on April 18, 2026 at 19:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Samsung Android firmware update SMR Jan-2026 Release 1 or any newer build to patch the SLocation access‑control flaw.
  • Disable or restrict the SLocation service via device settings or enterprise device management to reduce local privilege escalation risk.
  • If an update is not available, use device policy controls to limit or disable privileged API exposure, such as restricting SLocation functionality in managed profiles or via custom client settings.

Generated by OpenCVE AI on April 18, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Android SLocation Service Enables Local Privilege Escalation
Weaknesses CWE-284

Thu, 15 Jan 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung android
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:samsung:android:15.0:smr-apr-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-aug-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-dec-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-feb-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-jul-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-jun-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-mar-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-may-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-nov-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-oct-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-sep-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-aug-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-dec-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-nov-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-oct-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-sep-2025-r1:*:*:*:*:*:*
Vendors & Products Samsung android
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 09 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung mobile
Samsung mobile Devices
Vendors & Products Samsung
Samsung mobile
Samsung mobile Devices

Fri, 09 Jan 2026 06:30:00 +0000

Type Values Removed Values Added
Description Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Android Mobile Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-02-26T15:04:53.756Z

Reserved: 2025-12-11T01:33:35.798Z

Link: CVE-2026-20970

cve-icon Vulnrichment

Updated: 2026-01-09T13:30:37.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-09T07:16:03.400

Modified: 2026-01-15T19:33:43.077

Link: CVE-2026-20970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:30:08Z

Weaknesses