Junglewise Threat Intelligence

CVE-2026-21052: Samsung Mobile SemClipboardService path traversal

CVE-2026-21052 · Severity: info · CVSS 6.8 · Published 2026-07-10

Executive brief

A security vulnerability exists in the clipboard service of Samsung mobile devices running Android 14, 15, and 16. This flaw allows a malicious application already present on the device to bypass standard security restrictions and access sensitive system files. If exploited, this could lead to the unauthorized exposure of private data or system-level information.

Technical details

A path traversal vulnerability exists in the SemClipboardService component of Samsung Mobile devices. The flaw stems from insufficient validation of file paths, allowing a local attacker with basic privileges to navigate outside of intended directories. By exploiting this, an attacker can read arbitrary files with system-level privileges. The vulnerability affects devices running Android 14, 15, and 16 prior to the SMR July 2026 Release 1 update. Samsung has addressed this issue in the July 2026 security maintenance release.

Affected products

  • Samsung Mobile Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory
  • 2026-07-01: patched: SMR Jul-2026 Release 1

References