Description
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
Published: 2026-08-10
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Samsung's Galaxy Themes software before the Aug‑2026 release allows an attacker who gains physical access to a device to trigger arbitrary activity execution. The flaw permits the malicious actor to craft an input that is not validated correctly by the theme component, leading to uncontrolled launch of an Android activity. Because the vulnerability can be exploited with direct physical interaction, it primarily threatens device integrity and potentially user privacy, depending on which activity is launched.

Affected Systems

The vulnerability affects Samsung Mobile Devices running Galaxy Themes prior to the SMR Aug‑2026 Release 1. Users of older firmware or unpatched theme packages are at risk.

Risk and Exploitability

The CVSS score of 5.2 indicates a medium severity and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is physical; an adversary must have physical proximity to the device to supply the malformed input. There are no publicly disclosed exploits or detailed attack scripts, but once physical access is achieved, the information flow control around the theme handler can be bypassed to launch any activity granted to the system. Due to the lack of remote exploitability, the immediate risk to most users is constrained to scenarios where an attacker can physically interact with the device.

Generated by OpenCVE AI on August 10, 2026 at 09:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to SMR Aug‑2026 Release 1 firmware or newer, which includes the Galaxy Themes fix
  • If the device remains on an older firmware, contact Samsung support or follow the Samsung Mobile security update page
  • Prevent unauthorized physical access by enabling device lock, screen lock, and other security features

Generated by OpenCVE AI on August 10, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Galaxy Themes Improper Input Validation Enables Physical Attacker Arbitrary Activity Launch
Weaknesses CWE-20

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:11:41.585Z

Reserved: 2025-12-11T01:33:35.824Z

Link: CVE-2026-21073

cve-icon Vulnrichment

Updated: 2026-08-10T17:11:36.327Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation