CVE-2026-21106: Samsung Cloud Assistant vulnerability
Published Sep 9, 2026
·Updated
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Affected Software
1 affected component
Samsung Cloud Assistant<9.0.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Cloud Assistantto a version that resolves this vulnerability.Fixed in 9.0.5
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker must have local access to the affected device. The issue is exploitable through improper verification of intent by a broadcast receiver.
2
Which Samsung Cloud Assistant versions are affected?
Samsung Cloud Assistant versions prior to 9.0.5 are affected. Updating to version 9.0.5 or later addresses the issue.
3
What could an attacker do if exploitation succeeds?
A local attacker could disable enhanced data protection settings in Samsung Cloud Assistant.