Executive brief
Samsung's SystemUI, a core component of Android devices that manages the system interface and notifications, contains an access control flaw that allows local attackers to launch arbitrary applications and perform unauthorized actions. A user with physical access or existing access to the device could exploit this to bypass security restrictions and execute unintended functionality.
Technical details
The vulnerability is an improper access control issue in Samsung's SystemUI component, which runs with system-level privileges in Android. The flaw allows local attackers to bypass permission checks and launch arbitrary activities without proper authorization. This requires local access to the device but does not require elevated privileges. The vulnerability was patched in the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) and subsequent updates. Attackers could leverage this to circumvent device restrictions, launch privileged applications, or trigger unintended system functions.
Affected products
- Samsung SystemUI prior to SMR Sep-2026 Release 1
Timeline
- 2026-09-09: disclosed
- 2026-09: patched: Fixed in SMR Sep-2026 Release 1