What is CVE-2026-21060?
Improper input validation in Samsung Contacts before SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. Affected versions should be updated to the latest security maintenance release.
Azərbaycanca: Samsung Contacts tətbiqində düzgün giriş yoxlaması (improper input validation) zəifliyi fiziki hücumçulara müxtəlif istifadəçi profilləri arasında məlumatlara giriş imkanı verir. SMR Aug-2026 Release 1 yeniləməsindən əvvəlki versiyalar təsirlənir, cihazı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20; shared threat actor: physical attackers; shared vendor: Samsung
FAQ2
Which Samsung application is affected by CVE-2026-21060?
This vulnerability affects the Samsung Contacts application.
What can an attacker achieve by exploiting this vulnerability?
A physical attacker can access data across multiple user profiles.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.