Executive brief
Samsung Plus TV is a streaming service application used on Samsung smart devices. A vulnerability in versions prior to 1.0.28.6 could allow a remote attacker to access sensitive information due to improper data validation. This could lead to the exposure of private user data or system information, potentially compromising user privacy.
Technical details
An improper input validation vulnerability exists in the Samsung Plus TV application. The flaw allows a remote attacker to bypass security checks and access sensitive information. The attack requires some level of user interaction (UI:P) but can be executed over the network without prior authentication. Samsung has addressed this issue in version 1.0.28.6 by implementing stricter input validation routines. The vulnerability is tracked as SVE-2026-0590 by the vendor.
Affected products
- Samsung Plus TV prior to 1.0.28.6
Timeline
- 2026-06-02: advisory: Samsung published the initial security bulletin.
- 2026-06-05: disclosed: CVE record published to the NVD.