CVE-2026-21112 PUBLISHED

Assigner: SamsungMobile
Reserved: 11.12.2025 Published: 09.09.2026 Updated: 09.09.2026

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Samsung Mobile
Product Samsung Tips
Versions Default: affected
  • unaffected from Android 17 to * (excl.)

References

Problem Types

  • CWE-20: Improper Input Validation