Executive brief
Weaver is a security component in Samsung devices responsible for hardware-backed protection of sensitive data. An improper access control flaw allows local attackers to render affected devices inoperable, disrupting normal functionality and requiring intervention to restore service.
Technical details
This vulnerability stems from improper access control in the Weaver component, which implements hardware-backed keystore functionality on Samsung devices. The flaw allows local attackers (with access to the device) to trigger a denial of service condition that renders the device inoperable. The attack requires local access to the device and does not require elevated privileges or user interaction. Exploitation results in device inoperability, effectively a denial of service. The patch is available in Samsung Mobile's SMR Aug-2026 Release 1 and later firmware versions.
Affected products
- Samsung Weaver prior to SMR Aug-2026 Release 1
Timeline
- 2026-08-10: disclosed
- 2026-08: patched: Fixed in SMR Aug-2026 Release 1