Executive brief
Samsung Contacts is a core application on Samsung mobile devices used to store and manage contact information. A vulnerability in input validation allows a local attacker with access to the device to delete files with the elevated privileges of the Contacts application, potentially compromising system integrity or removing critical data without authorization.
Technical details
The vulnerability is an improper input validation flaw in Samsung Contacts that allows a local attacker to perform file deletion operations with the application's elevated privileges. The attack requires local access to the device. An authenticated or unprivileged local user can exploit this to delete files outside the normal permissions granted to user-level processes, leveraging the Contacts application's system-level access. The vulnerability was patched in the Samsung Mobile Security update (SMR) released in August 2026.
Affected products
- Samsung Contacts prior to SMR Aug-2026 Release 1
Timeline
- 2026-08-10: disclosed
- 2026-08: patched