Executive brief
Samsung DeX, a feature that allows mobile devices to provide a desktop-like experience, contains a security flaw that could allow someone with physical access to the device to view private notification content. This could lead to the exposure of sensitive information, such as message previews or authentication codes, even if the notifications were intended to be hidden. Users should apply the April 2026 security update to resolve this issue.
Technical details
An improper access control vulnerability exists in Samsung DeX before the SMR Apr-2026 Release 1 update. The flaw allows an attacker with physical access to the device to bypass intended restrictions and view notification content that is configured to be hidden. This is categorized as a local information disclosure vulnerability requiring physical proximity. Samsung has addressed this issue in the April 2026 Security Maintenance Release by improving access control logic within the DeX component.
Affected products
- Samsung DeX Prior to SMR Apr-2026 Release 1
Timeline
- 2026-04-13: disclosed: Initial disclosure by Samsung and NVD publication.
- 2026-04-13: advisory: Samsung Mobile Vendor Advisory published.