Executive brief
Samsung Cloud Assistant is a mobile app that manages enhanced data protection settings for Samsung devices. A flaw allows local attackers to send malicious broadcast messages that disable these protections without proper authorization, potentially exposing user data to other apps on the device.
Technical details
The vulnerability is an improper verification of intent in a broadcast receiver component within Samsung Cloud Assistant prior to version 9.0.5. The broadcast receiver fails to properly validate incoming intents before processing commands to disable enhanced data protection settings. This allows local attackers with access to the device to craft and send malicious broadcast intents that execute privileged operations. The attack requires local access to the device but no user interaction or authentication. The patch adds proper access control validation to the broadcast receiver intent handling.
Affected products
- Samsung Cloud Assistant prior to 9.0.5
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Version 9.0.5 resolves the vulnerability