Description
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
Published: 2026-08-10
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper input validation in the Samsung Message application. This weakness can be exploited to read or trigger sensitive data through crafted input. The main consequence is information disclosure to a malicious actor who can manipulate the input.

Affected Systems

Samsung mobile devices running the Message app that have not yet applied the SMR Aug‑2026 Release 1 update are vulnerable. All models with the legacy Message component that still ship prior to that firmware release fall into this scope.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.1, indicating moderate severity. EPSS data is not available, and it is not listed in the CISA KEV catalog, suggesting no publicly known exploits. An attacker would need physical access to the device and would need to supply malicious input via the Message interface to trigger the disclosure. The lack of network or user level access limits remote proliferation.

Generated by OpenCVE AI on August 10, 2026 at 09:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Samsung firmware update, ensuring the SMR Aug‑2026 Release 1 is installed.
  • If an update cannot be applied immediately, restrict physical access to the device and enforce a robust lock‑screen policy.
  • Monitor device logs for anomalous Message input activity and disable the Message app if the device is at high risk of physical compromise.

Generated by OpenCVE AI on August 10, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Samsung Message Allows Physical Attackers to Access Sensitive Information
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Weaknesses CWE-20
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:41:47.009Z

Reserved: 2025-12-11T01:33:35.824Z

Link: CVE-2026-21070

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation