Executive brief
Samsung Auto is a service used to integrate mobile device features with vehicle infotainment systems. A vulnerability in this application allows a malicious app installed on the same device to modify the vehicle's audio configuration without authorization. This could lead to unauthorized changes in sound settings or audio behavior while using the automotive interface.
Technical details
The vulnerability stems from the improper export of Android application components within the Samsung Auto app. Because these components are exported without sufficient access controls, other applications on the same device can interact with them. A local attacker with low privileges can exploit this to programmatically change the device's audio configuration. The issue affects Samsung Auto versions prior to 3.1.2.61 on Android 15 and 3.2.0.38 on Android 16. Samsung has addressed this by implementing proper access control mechanisms for the affected components.
Affected products
- Samsung Samsung Auto Prior to 3.1.2.61 (Android 15), prior to 3.2.0.38 (Android 16)
Timeline
- 2026-06-02: advisory: Samsung bulletin published
- 2026-06-05: disclosed: CVE published to NVD