Executive brief
Samsung Contacts is a core Android application used to manage and store contact information on Samsung mobile devices. This vulnerability allows a locally installed app to delete files with the same privileges as Samsung Contacts, potentially resulting in data loss, application malfunction, or unauthorized removal of user data.
Technical details
This is an improper export of Android application components vulnerability in Samsung Contacts. The root cause is the over-exposure of exported application components that lack proper permission checks, allowing other local applications to interact with them. An attacker with access to the local device (no network access required) can craft a malicious app to invoke these exported components and execute file deletion operations with Samsung Contacts' privileges. The vulnerability affects Samsung Contacts versions prior to SMR Aug-2026 Release 1 and has been patched in the August 2026 security update.
Affected products
- Samsung Contacts Prior to SMR Aug-2026 Release 1
Timeline
- 2026-08-10: disclosed
- 2026-08: patched: Fixed in SMR Aug-2026 Release 1