Junglewise Threat Intelligence

CVE-2026-21014: Samsung Camera improper access control in location data access

CVE-2026-21014 · Severity: low · CVSS 2.8 · Published 2026-04-13

Vendors: Samsung.

Executive brief

A vulnerability in the Samsung Camera app could allow a malicious application installed on the same device to access the user's location data. To exploit this, a user must interact with the device in a specific way. This could lead to a breach of privacy by exposing where photos or videos were taken.

Technical details

An improper access control vulnerability exists in the Samsung Camera application. A local attacker with low privileges can exploit this flaw to bypass intended restrictions and access sensitive location information. The attack requires user interaction to be successful. Samsung has addressed this issue in version 16.5.00.28 by implementing proper access control mechanisms. The vulnerability is tracked as SVE-2025-1890 by the vendor.

Affected products

  • Samsung Camera prior to 16.5.00.28

Timeline

  • 2026-04-07: advisory: Samsung published the security bulletin.
  • 2026-04-13: disclosed: CVE published to NVD.

References