Junglewise Threat Intelligence

CVE-2026-21025: Samsung Telephony incorrect privilege assignment

CVE-2026-21025 · Severity: info · CVSS 6.9 · Published 2026-06-05

Vendors: Samsung.

Executive brief

A security vulnerability in Samsung mobile devices' telephony component could allow an attacker with physical or local access to the device to view sensitive information. This component manages phone calls and cellular communication services. If exploited, this could lead to the unauthorized disclosure of private user data.

Technical details

An incorrect privilege assignment vulnerability exists within the Samsung Telephony component. The flaw allows a local attacker to bypass intended access controls due to improper permission settings. By exploiting this, an attacker can gain unauthorized access to sensitive information stored or processed by the telephony service. The vulnerability is addressed in the Samsung Security Maintenance Release (SMR) for June 2026.

Affected products

  • Samsung Telephony Prior to SMR Jun-2026 Release 1

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References