Executive brief
SemClipboardService is a Samsung system component that manages clipboard data access on mobile devices. A local authorization bypass allows unprivileged attackers to read sensitive information copied to the clipboard—such as passwords, authentication tokens, or personal data—without proper permissions, potentially enabling account compromise or data theft.
Technical details
An authorization bypass vulnerability in Samsung's SemClipboardService component fails to properly validate access permissions before exposing clipboard data to local processes. The vulnerability is exploitable by local attackers without elevated privileges, allowing them to read sensitive data stored in the clipboard. The fix is available in the August 2026 Security Maintenance Release (SMR) or later. No evidence of active exploitation in the wild has been reported.
Affected products
- Samsung SemClipboardService prior to SMR Aug-2026 Release 1
Timeline
- 2026-08-10: disclosed
- 2026-08: patched: SMR Aug-2026 Release 1