Executive brief
Samsung Dialer, the native phone application on Samsung mobile devices, contains an input validation flaw that allows attackers to remotely access SIM card-related functions without authorization. An attacker could potentially make unauthorized calls, send messages, or access sensitive SIM services, but user interaction is required to trigger the vulnerability.
Technical details
The vulnerability is an improper input validation issue in Samsung Dialer prior to the August 2026 Security Maintenance Release (SMR Aug-2026 Release 1). The flaw allows remote attackers to access SIM-related functions through crafted input, requiring user interaction to trigger exploitation. The exact attack vector and vulnerable component are not fully detailed in the advisory, but the impact is limited to SIM function access rather than full system compromise. A patch is available in the August 2026 security update.
Affected products
- Samsung Dialer prior to SMR Aug-2026 Release 1
Timeline
- 2026-08-10: disclosed
- 2026-08: patched: SMR Aug-2026 Release 1