SamsungCVE-2026-21059
Samsung Contacts: exported component
Medium6.9CVE-2026-21059 · Published Aug 10, 2026 · updated Aug 19, 2026
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-926
More Samsung advisories
All Samsung| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Samsung Smart Switch: improper input validation | Medium6.8 | No fix yet |
| Aug 10 | Samsung SmartThings: improper access control | Medium6.9 | No fix yet |
| Aug 10 | Samsung My Galaxy: improper authorization | Medium5.3 | No fix yet |
| Aug 10 | Samsung Health: improper authorization | Medium6.9 | No fix yet |
| Aug 10 | Samsung Health: improper authorization | Medium6.9 | No fix yet |
| Aug 10 | Samsung: insufficient authenticity check | Medium4.7 | No fix yet |