Executive brief
A vulnerability exists in the Retail Mode of Samsung mobile devices, which is a specialized mode used for floor models in retail stores. An attacker with physical access to a device can bypass intended restrictions to trigger sensitive system functions. This could lead to unauthorized access to device features or settings that are normally protected.
Technical details
An improper input validation vulnerability exists in the Retail Mode component of Samsung Android devices. The flaw allows a local or physical attacker with low privileges to bypass validation checks and execute privileged functions that should be restricted. The vulnerability is addressed in the Samsung Security Maintenance Release (SMR) for April 2026. While the NVD lists a local attack vector, the vendor-provided CVSS vector specifies physical access (AV:P) as a requirement for exploitation. An attacker could leverage this to gain unauthorized access to system-level capabilities on affected handsets.
Affected products
- Samsung Android Prior to SMR Apr-2026 Release 1
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory