Improper Authentication Vulnerability in Samsung ActivityTaskManagerService
CVE-2026-21097

4.6MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21097?

An improper authentication vulnerability in the ActivityTaskManagerService prior to the SMR September 2026 Release 1 permits local privileged attackers to launch arbitrary activities. This flaw can be exploited by attackers with local access to compromise device integrity, leading to unauthorized access and potential manipulation of sensitive operations.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14,15,16,17

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.