Junglewise Threat Intelligence

CVE-2026-21032: Samsung Assistant arbitrary script execution in SmartHomeWidgetReceiver

CVE-2026-21032 · Severity: info · CVSS 6.9 · Published 2026-06-05

Vendors: Samsung.

Executive brief

Samsung Assistant is a mobile application component used for managing device features and smart home widgets. A security flaw in how the app handles internal communications allows other malicious apps installed on the same device to execute unauthorized scripts. This could lead to unauthorized actions being performed on the device or the exposure of user data within the Assistant ecosystem.

Technical details

A vulnerability exists in the SmartHomeWidgetReceiver component of the Samsung Assistant application due to an improperly exported Android component. Because this component is exported without adequate access controls, a local malicious application can send crafted intents to the receiver. This allows an attacker to bypass intended security boundaries and execute arbitrary scripts within the context of the Samsung Assistant application. Samsung has addressed this in version 9.3.14 by implementing proper access control restrictions on the affected component.

Affected products

  • Samsung Assistant prior to 9.3.14

Timeline

  • 2026-06-02: advisory: Samsung published the initial bulletin.
  • 2026-06-05: disclosed: CVE published to the NVD dataset.

References