Improper Input Validation in Samsung Contacts Affects Local Security
CVE-2026-21058

6.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 August 2026

What is CVE-2026-21058?

Samsung Contacts prior to the SMR Aug-2026 Release 1 suffers from improper input validation, which can allow localized attackers to exploit this flaw to delete files with the privileges of the application. This vulnerability highlights the need for robust security measures in application design to prevent unauthorized access and actions.

Affected Version(s)

Samsung Mobile Devices SMR Aug-2026 Release in Android 16

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.