Junglewise Threat Intelligence

CVE-2026-21027: Samsung ImsSettings improper component export

CVE-2026-21027 · Severity: info · CVSS 4.8 · Published 2026-06-05

Vendors: Samsung.

Executive brief

A security issue in the Samsung ImsSettings application, which manages IP Multimedia Subsystem settings on mobile devices, could allow a local attacker to trigger internal logging functions. While this specific flaw is rated as low severity, it represents an improper configuration of application components that could potentially be used to gather diagnostic information or interfere with system logs. Users should apply the June 2026 security update to resolve this issue.

Technical details

A vulnerability exists in the Samsung ImsSettings application due to the improper export of Android components. This misconfiguration allows a local attacker with low privileges to interact with internal application components that should not be publicly accessible. Specifically, an attacker can trigger the application's logging functions. The issue is addressed in the Samsung SMR Jun-2026 Release 1 update. The CVSS 4.0 score of 4.8 reflects a local attack vector with low confidentiality impact and no impact on integrity or availability.

Affected products

  • Samsung ImsSettings prior to SMR Jun-2026 Release 1

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References