Junglewise Threat Intelligence

CVE-2026-21097: Samsung ActivityTaskManagerService improper authentication

CVE-2026-21097 · Severity: medium · CVSS 6.7 · Published 2026-09-09

Vendors: Samsung.

Executive brief

Samsung's ActivityTaskManagerService contains an authentication bypass that allows locally privileged attackers to launch arbitrary activities on Android devices. This could allow a malicious app with basic privileges to perform unauthorized actions, potentially leading to unauthorized access to device features, data exposure, or lateral privilege escalation.

Technical details

An improper authentication vulnerability exists in Samsung's ActivityTaskManagerService component, a core Android system service responsible for managing application activities and lifecycle. The vulnerability allows a local attacker with privileged access to bypass authentication checks and launch arbitrary activities without proper authorization. This requires local access and elevated privileges on the device. The impact is limited to local privilege escalation and unauthorized activity launch. Samsung has addressed this issue in the September 2026 SMR (Samsung Mobile Release) Release 1 and later.

Affected products

  • Samsung Android prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09-01: patched: Samsung Mobile Security Update - September 2026 Release 1

References