Executive brief
Samsung SpriteWallpaper, a component used for managing wallpapers on Samsung mobile devices, contains a security flaw that improperly exposes internal application components. This vulnerability allows a local attacker or a malicious app installed on the device to access sensitive information. Users should update their device firmware to the June 2026 Security Maintenance Release (SMR) or later to resolve this issue.
Technical details
A vulnerability exists in Samsung SpriteWallpaper due to the improper export of Android application components (such as Activities, Services, or Content Providers). By failing to restrict access to these components, the application allows other local applications on the device to interact with them without proper authorization. An attacker can exploit this to bypass intended access controls and retrieve sensitive information handled by the wallpaper component. The issue is addressed in the Samsung SMR Jun-2026 Release 1 update.
Affected products
- Samsung SpriteWallpaper prior to SMR Jun-2026 Release 1
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory
- 2026-06-05: patched: SMR Jun-2026 Release 1