Junglewise Threat Intelligence

CVE-2026-21060: Samsung Contacts improper input validation

CVE-2026-21060 · Severity: medium · CVSS 4.6 · Published 2026-08-10

Vendors: Samsung.

Executive brief

Samsung Contacts is a built-in application on Samsung devices that stores and manages phone numbers and contact information. A flaw in how the app validates user input allows someone with physical access to a device to read contact data belonging to other user profiles on the same device, potentially exposing personal information like names and phone numbers across multiple accounts.

Technical details

The vulnerability stems from improper input validation in Samsung Contacts. This allows attackers with physical access to the device to bypass access controls and read contact data across multiple user profiles. The attack vector is physical rather than remote, meaning an attacker must have direct access to the device. A patch is available in Samsung Mobile Security Release 1 for August 2026 (SMR Aug-2026 Release 1). No evidence of exploitation in the wild has been reported.

Affected products

  • Samsung Contacts prior to SMR Aug-2026 Release 1

Timeline

  • 2026-08-10: disclosed
  • 2026-08: patched: SMR Aug-2026 Release 1

References