Junglewise Threat Intelligence

CVE-2026-21098: Samsung Link to Windows improper access control

CVE-2026-21098 · Severity: info · Published 2026-09-09

Vendors: Samsung.

Executive brief

Link to Windows is a Samsung feature that enables users to manage their phone from a connected Windows PC. This vulnerability allows a local attacker on the same network to establish an unauthorized connection to a phone without the user's consent, potentially enabling unauthorized access to device features and data.

Technical details

An improper access control vulnerability in Samsung Link to Windows prior to the SMR Sep-2026 Release 1 update allows local attackers to establish connections with a paired Windows PC without proper user interaction or authentication. The vulnerability is exploitable from a local/network position and does not appear to require authentication bypass. A successful exploit could allow an attacker to establish unauthorized remote access to a connected device. The fix is available in the September 2026 security update.

Affected products

  • Samsung Link to Windows prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: SMR Sep-2026 Release 1

References