Junglewise Threat Intelligence

CVE-2026-21102: Samsung DualDAR use-after-free privilege escalation

CVE-2026-21102 · Severity: medium · CVSS 6.7 · Published 2026-09-09

Vendors: Samsung.

Executive brief

DualDAR is a Samsung security component used in mobile devices. A use-after-free memory vulnerability allows a locally authenticated privileged attacker to execute arbitrary code with root-level access, potentially compromising the entire device and any data stored on it.

Technical details

A use-after-free vulnerability exists in Samsung DualDAR prior to the SMR Sep-2026 Release 1 patch. The flaw allows a local attacker with elevated privileges to trigger memory corruption by accessing freed memory, enabling arbitrary code execution with root privilege. The vulnerability requires local access and elevated privileges as a precondition. The patch is available in the September 2026 security update (SMR Sep-2026 Release 1).

Affected products

  • Samsung DualDAR prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed

References