Junglewise Threat Intelligence

CVE-2026-21106: Samsung Cloud Assistant broadcast receiver verification bypass

CVE-2026-21106 · Severity: info · CVSS 0 · Published 2026-09-09

Vendors: Samsung.

Executive brief

Samsung Cloud Assistant is a mobile app that manages enhanced data protection settings for Samsung devices. A flaw allows local attackers to send malicious broadcast messages that disable these protections without proper authorization, potentially exposing user data to other apps on the device.

Technical details

The vulnerability is an improper verification of intent in a broadcast receiver component within Samsung Cloud Assistant prior to version 9.0.5. The broadcast receiver fails to properly validate incoming intents before processing commands to disable enhanced data protection settings. This allows local attackers with access to the device to craft and send malicious broadcast intents that execute privileged operations. The attack requires local access to the device but no user interaction or authentication. The patch adds proper access control validation to the broadcast receiver intent handling.

Affected products

  • Samsung Cloud Assistant prior to 9.0.5

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Version 9.0.5 resolves the vulnerability

References