Executive brief
Samsung Message is the built-in messaging application on Samsung mobile devices. A flaw in how it validates user input allows attackers with physical access to a device to read sensitive information, including private messages and user data. While this requires hands-on access rather than remote exploitation, it undermines the confidentiality of communications stored on the device.
Technical details
The vulnerability is an improper input validation flaw in Samsung Message. The attack vector is physical, requiring an attacker to have hands-on access to an affected device. By leveraging the input validation weakness, an attacker can bypass security checks and access sensitive information stored within the messaging application. The vulnerability affects Samsung Message versions prior to the August 2026 Security Maintenance Release (SMR) 1. A patch is available in the August 2026 SMR and later releases.
Affected products
- Samsung Message prior to SMR Aug-2026 Release 1
Timeline
- 2026-08-10: disclosed
- 2026-08: patched: Patch included in SMR Aug-2026 Release 1