Description
Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in the IAFDService component of Samsung Mobile Devices prior to the SMR Jul‑2026 Release 1 allows local privileged attackers to invoke privileged APIs. This flaw enables any process or user with local privilege to misuse these APIs, potentially allowing unauthorized actions that could affect the device’s operating system or applications.

Affected Systems

Samsung Mobile Devices operating with firmware released before the SMR Jul‑2026 Release 1 are affected. All devices running versions older than this update inherit the vulnerability in the IAFDService component.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local privileged access to exploit this flaw, limiting the threat to environments where local users can gain or already possess elevated privileges. The overall risk remains moderate, but patching is advised to prevent potential misuse of the privileged APIs.

Generated by OpenCVE AI on July 28, 2026 at 08:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Samsung Mobile SMR Jul-2026 Release 1 firmware update to patch the IAFDService component.
  • Restrict access to the privileged APIs by enforcing policy controls that align with CWE‑284, allowing only accounts that truly require them.
  • Disable or limit the use of IAFDService privileged APIs whenever possible to reduce attack surface.

Generated by OpenCVE AI on July 28, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile IAFDService Allows Local Privileged API Abuse
Weaknesses CWE-284

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Privileged API Abuse via Samsung IAFDService Access Control Flaw
Weaknesses CWE-284

Thu, 23 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Local Privileged API Abuse via Samsung IAFDService Access Control Flaw
Weaknesses CWE-284

Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung IAFDService Enables Local Privileged API Abuse
Weaknesses CWE-284

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung IAFDService Enables Local Privileged API Abuse
Weaknesses CWE-284

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in IAFDService Allows Local Privileged API Abuse
Weaknesses CWE-284

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in IAFDService Allows Local Privileged API Abuse
Weaknesses CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile IAFDService Allows Local Privileged API Abuse
Weaknesses CWE-284

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile IAFDService Allows Local Privileged API Abuse
Weaknesses CWE-284

Fri, 10 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T14:30:55.833Z

Reserved: 2025-12-11T01:33:35.815Z

Link: CVE-2026-21040

cve-icon Vulnrichment

Updated: 2026-07-10T14:30:48.854Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses