Junglewise Threat Intelligence

CVE-2026-21009: Samsung Android App Pinning bypass in Recents

CVE-2026-21009 · Severity: medium · CVSS 6.8 · Published 2026-04-13

Vendors: Samsung.

Executive brief

A security vulnerability exists in Samsung mobile devices that could allow an individual with physical access to the phone to bypass the 'App Pinning' security feature. App Pinning is designed to lock the device to a single application to prevent users from accessing other data or apps. By exploiting this flaw, an unauthorized person holding the device could potentially exit the pinned app and gain access to the rest of the phone's contents.

Technical details

A vulnerability classified as 'Improper Check for Unusual or Exceptional Conditions' (CWE-754) exists in the Recents component of Samsung's Android implementation. The flaw is rooted in an improper check for exceptional conditions within the task switcher logic. A physical attacker with access to the device can exploit this to bypass App Pinning restrictions, which are intended to restrict the user to a single foreground task. This bypass could lead to unauthorized access to other applications and sensitive user data. The issue is resolved in the SMR Apr-2026 Release 1 update.

Affected products

  • Samsung Android Prior to SMR Apr-2026 Release 1

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory: Samsung released the SMR Apr-2026 Release 1 update.

References