Executive brief
Samsung Members is a support and community application for Samsung device users. A vulnerability in this app allowed a malicious local application to redirect the user to unauthorized web addresses or trigger internal app functions without permission. This could potentially be used to bypass security boundaries or perform actions on the device using the app's elevated privileges.
Technical details
An improper input validation vulnerability exists in the Samsung Members application. A local attacker with low privileges can exploit this flaw to bypass intended restrictions, allowing them to load arbitrary URLs or launch internal application activities. By leveraging the application's existing permissions, an attacker could perform unauthorized actions or access restricted components. The vulnerability is addressed in version 5.8.01.5 by implementing stricter input validation checks.
Affected products
- Samsung Samsung Members prior to 5.8.01.5
Timeline
- 2026-06-02: advisory: Samsung Mobile Security bulletin published
- 2026-06-05: disclosed: CVE published to NVD