CVE-2026-21027
Improper Component Export in ImsSettings Prior to SMR Jun-2026
Publication date: 2026-06-05
Last updated on: 2026-06-05
Assigner: Samsung Mobile
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | imssettings | to 2026-06-01 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves an improper export of Android application components in the ImsSettings application prior to the SMR Jun-2026 Release 1. Because of this improper export, local attackers can trigger a logging function that they should not normally have access to.
How can this vulnerability impact me? :
The impact of this vulnerability is that a local attacker could exploit the improperly exported components to trigger logging functions. This could potentially lead to unauthorized access to logging data or unintended behavior in the application, which might affect system stability or privacy.