Junglewise Threat Intelligence

CVE-2026-21054: Samsung InputSharing improper export of components

CVE-2026-21054 · Severity: info · CVSS 6.9 · Published 2026-07-10

Vendors: Samsung.

Executive brief

Samsung InputSharing is a mobile application component used for sharing data between devices or inputs. A vulnerability in versions prior to 2.7.01.4 allows a malicious application installed on the same device to access shared data without permission. This could lead to the exposure of sensitive information handled by the sharing service.

Technical details

The vulnerability stems from the improper export of Android application components within the InputSharing app. Because these components were exported without adequate access controls, other applications on the same device can interact with them. A local attacker can exploit this to bypass intended isolation and access data being processed or shared by the application. Samsung has addressed this in version 2.7.01.4 by implementing proper access control restrictions on the affected components.

Affected products

  • Samsung Mobile InputSharing prior to 2.7.01.4

Timeline

  • 2026-07-07: advisory: Samsung Mobile bulletin published
  • 2026-07-10: disclosed: NVD publication date

References