Junglewise Threat Intelligence

CVE-2026-21099: Samsung SettingsProvider improper access control

CVE-2026-21099 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Vendors: Samsung.

Executive brief

Samsung SettingsProvider is a system component that manages device settings on Android devices. An improper access control vulnerability allows a local attacker with access to the device to read sensitive configuration information they should not be able to access, potentially exposing user data or device settings.

Technical details

The vulnerability is an improper access control flaw in SettingsProvider, a system service component in Samsung Android devices. The root cause involves insufficient permission checks when accessing sensitive settings data. An attacker with local access to the device (e.g., a malicious app with appropriate permissions or physical access) can bypass access controls to read sensitive information. The attack requires local system access and does not require network connectivity. Samsung patched this issue in the September 2026 Security Update Release 1 (SMR Sep-2026 Release 1).

Affected products

  • Samsung Android OS prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: SMR Sep-2026 Release 1

References