Executive brief
A security vulnerability exists in the Wallpaper service on Samsung mobile devices running Android 14, 15, and 16. This flaw could allow a local attacker with high-level privileges to bypass security restrictions and access sensitive system files. Such access could lead to the exposure of private data or critical system information, potentially compromising the integrity of the device.
Technical details
A path traversal vulnerability exists in the Samsung Wallpaper service. The root cause is insufficient validation of file paths, which allows a local attacker with high privileges (PR:H) to navigate outside of intended directories. By exploiting this flaw, an attacker can read arbitrary files with the elevated permissions of the system server. This vulnerability affects Samsung mobile devices running Android versions 14, 15, and 16. The issue is addressed in the SMR Jul-2026 Release 1 security update.
Affected products
- Samsung Mobile Android 14, 15, 16 Prior to SMR Jul-2026 Release 1
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory