Description
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when Samsung Contacts improperly exports Android application components, allowing a local attacker to delete a file using the app’s privileges. This flaw corresponds to CWE-926 and can compromise data integrity by removing files that should have been protected under normal application permissions.

Affected Systems

Samsung mobile devices that run versions of Samsung Contacts prior to the SMR Aug‑2026 Release 1 update are impacted. The issue is limited to the Contacts application bundled with Samsung’s mobile platform; other applications are not directly affected.

Risk and Exploitability

The CVSS score of 6.9 labels the flaw as moderate. EPSS is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of exploitation. The attack vector is inferred to be local – an attacker must have physical or local software access to trigger the exported component. If enabled, the attacker could delete files within the scope of the Contacts app’s privileges, potentially removing important data.

Generated by OpenCVE AI on August 10, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Samsung Mobile’s official security update (SMR Aug‑2026 Release 1) to fix the improper export issue.
  • If the update is not available, uninstall or disable the legacy Samsung Contacts application to eliminate the vulnerability.
  • Monitor device activity for unusual file deletion events that may indicate exploitation.

Generated by OpenCVE AI on August 10, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung android
CPEs cpe:2.3:o:samsung:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-apr-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-aug-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-dec-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-feb-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-jan-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-jul-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-jun-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-mar-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-may-2026-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-nov-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-oct-2025-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:smr-sep-2025-r1:*:*:*:*:*:*
Vendors & Products Samsung
Samsung android
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Mon, 10 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local File Deletion via Improper Export of Samsung Contacts Components

Mon, 10 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-926
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local File Deletion via Improper Export of Samsung Contacts Components

Mon, 10 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Android
Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T16:30:50.535Z

Reserved: 2025-12-11T01:33:35.821Z

Link: CVE-2026-21059

cve-icon Vulnrichment

Updated: 2026-08-10T16:29:05.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-10T08:16:47.947

Modified: 2026-08-19T01:07:38.257

Link: CVE-2026-21059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T20:15:03Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components