← All Advisories

Samsung Contacts improper component export allows local attacker to delete files using app privilege

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-21059

Key Details

CVECVE-2026-21059
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-08-19
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsSamsung android
Classified asCWE-926 (Improper Export of Android Application Components)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Samsungandroid
SubsystemsGeneral OT
SectorsMultiple

What to Know

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

What to Do

Monitor Samsung's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21059
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21059
Vendor advisoryhttps://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=08