Executive brief
A security vulnerability in the LocationManager component of Samsung Android devices could allow a malicious application installed on the device to access sensitive information. This occurs due to incorrect permission settings within the system's location services. An attacker could exploit this to bypass intended privacy protections and gather data they should not have access to.
Technical details
An incorrect privilege assignment vulnerability exists in the Samsung LocationManager component. The flaw stems from improper permission checks or assignments, allowing a local attacker with low privileges to bypass intended access controls. By exploiting this issue, a malicious application can gain unauthorized access to sensitive information managed by the location service. The vulnerability is addressed in the Samsung Security Maintenance Release (SMR) for May 2026. The attack requires local execution but no user interaction.
Affected products
- Samsung Android 14.0 Prior to SMR May-2026 Release 1
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory
- 2026-05-13: patched: Included in SMR May-2026 Release 1