Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Cross‑Profile Data Access via Improper Input Validation in Samsung Contacts | |
| Weaknesses | CWE-20 CWE-284 |
Mon, 10 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: SamsungMobile
Published:
Updated: 2026-08-10T07:39:55.595Z
Reserved: 2025-12-11T01:33:35.821Z
Link: CVE-2026-21060
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T08:30:04Z