Executive brief
The Galaxy Editing Service, a component on Samsung mobile devices used for media editing, contains a vulnerability where internal application components are improperly exposed. This allows a malicious app installed on the same device to bypass security boundaries and perform unauthorized actions with elevated privileges. Users should update to the June 2026 security patch to resolve this issue.
Technical details
A vulnerability exists in the Samsung Galaxy Editing Service due to the improper export of Android application components. By failing to restrict access to these components, the application allows other locally installed applications to interact with its internal interfaces. A local attacker with low privileges can exploit this to trigger privileged operations that should otherwise be restricted. This issue is addressed in the Samsung SMR Jun-2026 Release 1 update.
Affected products
- Samsung Galaxy Editing Service Prior to SMR Jun-2026 Release 1
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory
- 2026-06-05: patched: SMR Jun-2026 Release 1