Description
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
Published: 2026-04-13
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Update
AI Analysis

Impact

Samsung DeX suffers from an improper access control flaw that enables an attacker who can physically reach the device to view the contents of notifications that are intended to be hidden. Because the flaw gives unauthorized visibility into user data, the attack results in the disclosure of potentially sensitive information.

Affected Systems

All Samsung mobile devices running Samsung DeX versions that were released before the SMR Apr‑2026 Release 1 update are vulnerable. Devices using earlier releases of DeX are therefore at risk.

Risk and Exploitability

The vulnerability has a CVSS score of 4.7, placing it in the moderate range. No EPSS score is available, and it is not listed in the CISA KEV catalog. The flaw requires physical proximity to the device, meaning an attacker must be present near the device to exploit it. The limited impact and lack of remote exploitation reduce the overall risk, but exposure of private notification content still warrants prompt remediation.

Generated by OpenCVE AI on April 13, 2026 at 07:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung DeX to the SMR Apr‑2026 Release 1 version or later through Samsung’s security update portal.
  • Restrict physical access to the device’s screen and surrounding area to prevent unauthorized observation of notifications.
  • If an immediate update is not possible, ensure that personal data requiring privacy is not displayed on the device while unattended.

Generated by OpenCVE AI on April 13, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung android
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:samsung:android:15.0:-:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-apr-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-aug-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-dec-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-feb-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-feb-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-jan-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-jan-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-jul-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-jun-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-mar-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-mar-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-may-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-nov-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-oct-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:smr-sep-2025-r1:*:*:*:*:*:*
Vendors & Products Samsung android
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Samsung DeX Improper Access Control Exposes Hidden Notifications to Physical Attackers
Weaknesses CWE-200
CWE-284

Mon, 13 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung mobile Devices
Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung
Samsung mobile Devices
Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 13 Apr 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
References
Metrics cvssV4_0

{'score': 4.7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Samsung Android Mobile Devices
Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-04-13T18:06:16.870Z

Reserved: 2025-12-11T01:33:35.803Z

Link: CVE-2026-21006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-04-13T06:16:05.003

Modified: 2026-04-13T18:38:14.630

Link: CVE-2026-21006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T12:53:00Z