Executive brief
A security vulnerability in Samsung's Routines feature could allow an unauthorized person with local access to a device to view sensitive information. This issue stems from how the system handles permissions, potentially exposing private data to local attackers. Users should update their Samsung mobile devices to the May 2026 security release or later to resolve this issue.
Technical details
A vulnerability exists in the Samsung Routines component due to improper handling of insufficient permissions. A local attacker with low privileges can exploit this flaw to bypass intended access controls and retrieve sensitive information from the device. The vulnerability affects Samsung devices running Android 15 and 16. The issue is addressed in the Samsung Security Maintenance Release (SMR) for May 2026 (Release 1), which implements improved permission validation logic.
Affected products
- Samsung Android 15.0 Prior to SMR May-2026 Release 1
- Samsung Android 16.0 Prior to SMR May-2026 Release 1
Timeline
- 2026-05-13: advisory: Initial publication of the advisory by Samsung and NVD.
- 2026-05-13: patched: Fix released in SMR May-2026 Release 1.