Executive brief
A security vulnerability exists in Samsung mobile devices when they are in Maintenance mode. A person with physical access to the device could bypass the 'Extend Unlock' (formerly Smart Lock) security feature, potentially gaining unauthorized access to the device's functions or data. This issue is resolved in the April 2026 security update.
Technical details
An incorrect privilege assignment vulnerability (CWE-732) exists in the Bluetooth component of Samsung Android 14.0 devices when operating in Maintenance mode. The flaw allows a physical attacker to bypass the 'Extend Unlock' mechanism, which is designed to keep a device unlocked under trusted conditions. The vulnerability is triggered due to improper permission handling during this specific diagnostic state. An attacker with physical access can exploit this to gain unauthorized access to the device without the required authentication. The issue is addressed in the Samsung SMR Apr-2026 Release 1 firmware update.
Affected products
- Samsung Android 14.0 (Samsung devices) Prior to SMR Apr-2026 Release 1
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory