Insufficient Privileges Vulnerability in Samsung SecTelephonyProvider
CVE-2026-21017
4.6MEDIUM
What is CVE-2026-21017?
The SecTelephonyProvider in Samsung devices prior to the June 2026 Release 1 is vulnerable due to improper handling of insufficient privileges. This flaw allows local attackers to potentially gain unauthorized access to sensitive and privileged files, posing a security risk. Users should ensure their devices are updated to mitigate this vulnerability.
Affected Version(s)
Samsung Mobile Devices SMR Jun-2026 Release in Android 14, 15, 16