Path Traversal Vulnerability in ImsService by Samsung
CVE-2026-21092
8.8HIGH
What is CVE-2026-21092?
A path traversal vulnerability exists in ImsService, which enables remote attackers to manipulate file paths. This can allow unauthorized creation of image files with elevated system server privileges, potentially compromising the integrity of the system. Users are advised to update to the SMR Sep-2026 Release 1 to mitigate this risk.
Affected Version(s)
Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17