CVE-2026-21038
Awaiting Analysis Awaiting Analysis - Queue
Improper Input Validation in Samsung Android USB Driver

Publication date: 2026-06-05

Last updated on: 2026-06-05

Assigner: Samsung Mobile

Description
Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-05
Last Modified
2026-06-05
Generated
2026-06-25
AI Q&A
2026-06-05
EPSS Evaluated
2026-06-24
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
samsung android_usb_driver 1.9.5.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is caused by improper input validation in the Samsung Android USB Driver for Windows versions prior to 1.9.5.0. It allows a local attacker to access out-of-bounds memory, which means the attacker can read or potentially manipulate memory outside the intended boundaries.

Impact Analysis

The impact of this vulnerability is that a local attacker could exploit it to access memory outside the intended range. This could lead to unauthorized access to sensitive information or cause the system to behave unpredictably, potentially leading to crashes or other security issues.

Mitigation Strategies

To mitigate this vulnerability, update the Samsung Android USB Driver for Windows to version 1.9.5.0 or later, as versions prior to 1.9.5.0 are affected by improper input validation allowing local attackers to access out-of-bounds memory.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart