Executive brief
The Samsung Print Service Plugin for Android, a tool used to enable printing from mobile devices to Samsung and HP printers, contains a security flaw that could allow sensitive information to be accessed by unauthorized parties. An attacker with local access to a mobile device could potentially view data that should be protected. HP has released an update to the application to address this issue and protect user data.
Technical details
The Samsung Print Service Plugin for Android is vulnerable to information disclosure (CWE-926) due to the improper export of Android application components. This flaw allows a local attacker or a malicious application on the same device to interact with exported components that should have been restricted, potentially leading to the unauthorized retrieval of sensitive information. The vulnerability is present in versions of the plugin prior to 3.12.260420. HP has mitigated this issue in version 3.12.260420 and later; users are advised to update the application via the Google Play Store or Galaxy Store.
Affected products
- HP Samsung Print Service Plugin Versions prior to 3.12.260420
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-05-11: other: NVD analysis completed