CVE-2026-21034: Medium severity Samsung Samsung Auto (Android 15) vulnerability
Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Autoto a version that resolves this vulnerability.Fixed in 3.1.2.61 - Upgrade
Upgrade
Samsung Autoto a version that resolves this vulnerability.Fixed in 3.2.0.38
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21034?
CVE-2026-21034 has a medium severity rating with a CVSS score of 4.8.
How do I fix CVE-2026-21034?
To mitigate CVE-2026-21034, users should update Samsung Auto to version 3.1.2.61 for Android 15 or 3.2.0.38 for Android 16.
What kind of attack does CVE-2026-21034 allow?
CVE-2026-21034 allows a local attacker to change audio configuration due to improper export of application components.
Which versions of Samsung Auto are affected by CVE-2026-21034?
CVE-2026-21034 affects Samsung Auto versions prior to 3.1.2.61 on Android 15 and 3.2.0.38 on Android 16.
What components are improperly exported in CVE-2026-21034?
CVE-2026-21034 involves improper export of Android application components in Samsung Auto.