Junglewise Threat Intelligence

CVE-2026-21057: Samsung Pass out-of-bounds write due to improper input validation

CVE-2026-21057 · Severity: info · CVSS 6.8 · Published 2026-07-10

Vendors: Samsung.

Executive brief

Samsung Pass, a password management service for Samsung devices, contains a vulnerability that could allow a local attacker with high privileges to corrupt system memory. If exploited, this could lead to application crashes or potentially allow the attacker to gain further control over the device's operations. This issue affects the integrity and availability of the password management service.

Technical details

An out-of-bounds (OOB) write vulnerability exists in Samsung Pass due to improper input validation. A local attacker with high privileges (PR:H) can exploit this flaw to write data beyond the boundaries of allocated memory buffers. This memory corruption can lead to a denial of service (system instability/crashes) or potentially arbitrary code execution within the context of the application. The vulnerability is addressed in Samsung Pass version 5.2.10.3 by implementing stricter input validation checks.

Affected products

  • Samsung Mobile Samsung Pass prior to 5.2.10.3

Timeline

  • 2026-07-07: advisory: Samsung Mobile security bulletin published
  • 2026-07-10: disclosed: NVD publication date

References