Junglewise Threat Intelligence

CVE-2026-21063: Samsung AppLock improper component export allows physical bypass

CVE-2026-21063 · Severity: medium · CVSS 6.1 · Published 2026-08-10

Vendors: Samsung.

Executive brief

Samsung AppLock is a built-in Android application that protects sensitive apps by requiring authentication to open them. A vulnerability in how the app exports its components allows attackers with physical access to a device to bypass the app lock protection entirely, gaining unauthorized access to protected applications.

Technical details

The vulnerability is an improper export of Android application components in Samsung AppLock prior to the August 2026 Security Maintenance Release (SMR). The affected components are insufficiently protected, allowing them to be invoked by other applications or processes without proper authorization checks. An attacker with physical access to the device can exploit this by directly invoking the exported components to bypass the app lock function. The issue is resolved in AppLock versions included in the August 2026 SMR and later.

Affected products

  • Samsung AppLock prior to SMR Aug-2026 Release 1

Timeline

  • 2026-08-10: disclosed

References