Junglewise Threat Intelligence

CVE-2026-21041: Samsung SamsungSEAgentService improper access control

CVE-2026-21041 · Severity: info · CVSS 6.9 · Published 2026-07-10

Executive brief

A security vulnerability exists in the SamsungSEAgentService on Samsung mobile devices running Android 15 and 16. This flaw allows a local attacker or a malicious application installed on the device to bypass access controls and view sensitive information. This could lead to the unauthorized exposure of private user data or system details.

Technical details

An improper access control vulnerability exists within the SamsungSEAgentService component of Samsung mobile devices. The flaw allows a local attacker to bypass intended restrictions and gain unauthorized access to sensitive information. The vulnerability is triggered locally and does not require specific user interaction or elevated privileges (PR:N/UI:N). According to the vendor's CVSS 4.0 assessment, the impact is limited to high confidentiality loss (VC:H) with no impact on integrity or availability. The issue is addressed in the Samsung Security Maintenance Release (SMR) for July 2026.

Affected products

  • Samsung Mobile Samsung Mobile Devices (Android 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References