Junglewise Threat Intelligence

CVE-2026-20994: Samsung Account URL redirection and token theft

CVE-2026-20994 · Severity: info · CVSS 6.9 · Published 2026-03-16

Vendors: Samsung.

Executive brief

Samsung Account is a service used on Samsung devices to manage user profiles, sync data, and provide access to various Samsung services. A security flaw in versions prior to 15.5.01.1 could allow a malicious application installed on the same device to redirect web traffic and potentially steal the user's account access token. This could lead to unauthorized access to the user's personal account data and linked services.

Technical details

An open redirect vulnerability (CWE-601) exists in the Samsung Account application due to insufficient URL validation. A local attacker (e.g., a malicious app on the device) can exploit this by triggering a redirection to an untrusted site. This redirection can be leveraged to intercept sensitive account access tokens. The vulnerability was addressed in version 15.5.01.1 by implementing proper URL validation logic. While initially reported as a remote issue, the advisory was updated to clarify that the attack vector is local.

Affected products

  • Samsung Samsung Account prior to 15.5.01.1

Timeline

  • 2026-03-03: advisory: Initial bulletin published by Samsung Mobile Security
  • 2026-03-16: disclosed: CVE published to NVD
  • 2026-05-20: other: Advisory updated to change attack vector from remote to local

References

Related threats