Junglewise Threat Intelligence

CVE-2026-21028: Samsung AuditLogService improper access control

CVE-2026-21028 · Severity: info · CVSS 5.1 · Published 2026-06-05

Vendors: Samsung.

Executive brief

A security vulnerability exists in the AuditLogService of Samsung mobile devices, which is responsible for recording system events and security logs. An attacker with local access to the device could bypass security controls to view sensitive information that should be protected. This could lead to the exposure of private data or system details that could be used to facilitate further attacks.

Technical details

An improper access control vulnerability exists within the AuditLogService component of Samsung's Android implementation. The flaw allows a local attacker to bypass intended restrictions to read sensitive log data or system information. The vulnerability is triggered by insufficient permission checks within the service, enabling unauthorized access without requiring elevated privileges or user interaction. Samsung has addressed this issue in the June 2026 Security Maintenance Release (SMR).

Affected products

  • Samsung Android OS Prior to SMR Jun-2026 Release 1

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References