Executive brief
A vulnerability in the Samsung FactoryCamera application could allow a local attacker to access a device's unique identifier. This application is typically used for hardware testing and diagnostics on Samsung mobile devices. Unauthorized access to unique identifiers can be used to track users or compromise device privacy.
Technical details
A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in the Samsung FactoryCamera component. The flaw allows a local attacker with low privileges to bypass intended access controls and retrieve a unique device identifier. The issue is triggered by insecure default permission settings that fail to restrict access to sensitive diagnostic data. Samsung addressed this in the May 2026 Security Maintenance Release (SMR) by implementing stricter permission checks.
Affected products
- Samsung FactoryCamera Prior to SMR May-2026 Release 1
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory
- 2026-05-13: patched: Included in SMR May-2026 Release 1