Executive brief
A vulnerability in Samsung's AODManager (Always On Display) allows a local attacker with existing privileges to create files with system-level permissions. This could potentially be used to interfere with system operations or modify protected configurations. Users should apply the April 2026 security maintenance release to resolve this issue.
Technical details
The vulnerability is classified as an 'External Control of File Name or Path' issue within the AODManager component of Samsung Android devices. A local attacker who already possesses elevated privileges can exploit this flaw to specify a filename that the system then creates using high-level 'system' privileges. This root cause is likely a lack of sanitization or validation of user-supplied file paths before they are passed to a privileged file creation routine. The exploit requires local access and existing privileges, limiting its impact primarily to privilege escalation or persistence. Samsung addressed this in the SMR Apr-2026 Release 1 update.
Affected products
- Samsung Android Prior to SMR Apr-2026 Release 1
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory