Executive brief
A security vulnerability exists in the telephony component of Samsung mobile devices. This flaw could allow a local attacker or a malicious application to access sensitive system files that should normally be protected. If exploited, this could lead to the unauthorized disclosure of private information or interference with phone services.
Technical details
A vulnerability in the SecTelephonyProvider component of Samsung Android devices stems from improper handling of insufficient privileges. A local attacker can exploit this flaw to bypass intended access controls and read or interact with privileged files. The attack requires local access and some level of user interaction (UI:A). The issue is addressed in the Samsung Security Maintenance Release (SMR) for June 2026.
Affected products
- Samsung Android Devices Prior to SMR Jun-2026 Release 1
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory