Executive brief
A vulnerability in the Samsung Camera app could allow a malicious application installed on the same device to access the user's location data. To exploit this, a user must interact with the device in a specific way. This could lead to a breach of privacy by exposing where photos or videos were taken.
Technical details
An improper access control vulnerability exists in the Samsung Camera application. A local attacker with low privileges can exploit this flaw to bypass intended restrictions and access sensitive location information. The attack requires user interaction to be successful. Samsung has addressed this issue in version 16.5.00.28 by implementing proper access control mechanisms. The vulnerability is tracked as SVE-2025-1890 by the vendor.
Affected products
- Samsung Camera prior to 16.5.00.28
Timeline
- 2026-04-07: advisory: Samsung published the security bulletin.
- 2026-04-13: disclosed: CVE published to NVD.