Junglewise Threat Intelligence

CVE-2026-21008: Samsung S Share sensitive information disclosure

CVE-2026-21008 · Severity: medium · CVSS 6.5 · Published 2026-04-13

Vendors: Samsung.

Executive brief

A security vulnerability in Samsung's S Share feature could allow an attacker in close physical proximity to access sensitive information on a user's device. This issue affects Samsung mobile devices running Android 14 and earlier versions. Users should apply the April 2026 security maintenance release to protect their data from unauthorized local access.

Technical details

An information disclosure vulnerability exists in the Samsung S Share component due to improper handling of sensitive data. An attacker located on the same local network or within radio range (adjacent) can exploit this flaw to intercept or access sensitive information without requiring prior authentication or user interaction. The vulnerability is addressed in the Samsung Security Maintenance Release (SMR) for April 2026. Affected devices include those running Samsung's distribution of Android 14.0.

Affected products

  • Samsung Android Prior to SMR Apr-2026 Release 1

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-01: patched: Patched in SMR Apr-2026 Release 1

References