Executive brief
A security vulnerability in Samsung mobile devices could allow an individual with physical access to the phone to bypass network restrictions. This means a person holding the device could potentially circumvent security controls intended to limit network connectivity or data usage. The issue is resolved in the April 2026 security update.
Technical details
An improper input validation vulnerability exists in the handling of data related to network restrictions in Samsung's Android implementation. The flaw allows a physical attacker—someone with direct access to the device—to bypass configured network limitations. The root cause is insufficient validation of input data within the network restriction component. An attacker can exploit this to gain unauthorized network access or bypass administrative controls. The vulnerability is addressed in the Samsung Security Maintenance Release (SMR) for April 2026.
Affected products
- Samsung Android Prior to SMR Apr-2026 Release 1
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory