Use After Free Vulnerability in Samsung DualDAR Software
CVE-2026-21102

9.3CRITICAL

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21102?

A use after free vulnerability exists in Samsung's DualDAR software that allows local privileged attackers to execute arbitrary code with elevated privileges. This issue affects versions prior to the SMR September 2026 Release 1, where proper memory management is not enforced, potentially enabling unauthorized access and exploitation of system resources.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.