Description
Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability results from improper export of Android application components in Samsung Mobile's InputSharing application. An attacker with local access to a device can exploit the exposed components to read sharing data that is intended to remain private, leading actors to bypass component visibility restrictions and gain unauthorized data access.

Affected Systems

Samsung Mobile InputSharing affected. Devices running any version prior to 2.7.01.4 on Android are vulnerable. The issue is specific to the application bundled with Samsung Mobile devices.

Risk and Exploitability

The CVSS score of 6.9 represents moderate severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw requires local device access, an attacker who gains local access can read or exfiltrate sharing data via the exported components. No known public exploitation, and the impact is limited to information disclosure rather than code execution.

Generated by OpenCVE AI on July 29, 2026 at 11:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Mobile InputSharing to version 2.7.01.4 or later.
  • If an upgrade is not possible, remove or disable the InputSharing application until a fixed version is available.
  • Review the application’s manifest and ensure that sensitive components are not exported, following best practices for component privacy.

Generated by OpenCVE AI on July 29, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Local Data Exposure via Improper Export of Samsung InputSharing Components
Weaknesses CWE-200

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Data Exposure via Improper Export of Samsung InputSharing Components
Weaknesses CWE-200

Wed, 22 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local Data Leakage from Improperly Exported InputSharing Components
Weaknesses CWE-200
CWE-284

Fri, 17 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Data Leakage from Improperly Exported InputSharing Components
Weaknesses CWE-200
CWE-284

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Enables Local Data Access in Samsung Mobile InputSharing
Weaknesses CWE-200
CWE-285

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Enables Local Data Access in Samsung Mobile InputSharing
Weaknesses CWE-200
CWE-285

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components in Samsung InputSharing Enables Local Data Access
Weaknesses CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components in Samsung InputSharing Enables Local Data Access
Weaknesses CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Export of InputSharing Application Components Enabling Local Data Access
Weaknesses CWE-200

Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper Export of InputSharing Application Components Enabling Local Data Access
Weaknesses CWE-200

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile inputsharing
Vendors & Products Samsung Mobile
Samsung Mobile inputsharing

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Inputsharing
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T11:40:14.374Z

Reserved: 2025-12-11T01:33:35.820Z

Link: CVE-2026-21054

cve-icon Vulnrichment

Updated: 2026-07-10T11:39:58.252Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses

No weakness.