Junglewise Threat Intelligence

CVE-2026-21039: Samsung Mobile Devices improper access control in Settings

CVE-2026-21039 · Severity: info · CVSS 6.9 · Published 2026-07-10

Executive brief

A security vulnerability in Samsung mobile devices could allow a person with physical or local access to the device to modify theft protection settings without proper authorization. This could potentially allow an unauthorized user to disable or reconfigure security features intended to protect the device if it is lost or stolen. Users should update their devices to the July 2026 security maintenance release to resolve this issue.

Technical details

An improper access control vulnerability exists in the Settings application of Samsung mobile devices running Android 15 and 16. The flaw allows a local attacker to bypass intended restrictions and modify 'Theft protection' configurations. This is categorized as a high-integrity impact (VI:H) under CVSS 4.0 because it compromises the security controls designed to prevent unauthorized device use after theft. The issue is addressed in the Samsung Security Maintenance Release (SMR) for July 2026 (Release 1).

Affected products

  • Samsung Mobile Samsung Mobile Devices Prior to SMR Jul-2026 Release 1 (Android 15, 16)

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References