CVE-2026-21112: Input Validation
Published Sep 9, 2026
·Updated
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
Affected Software
1 affected component
Samsung Tips<Android 17
Event History
Sep 9, 2026
CVE Published
via MITRE·04:48 AM
Data Sourced
via MITRE·04:48 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local access to the affected device. Exploitation also requires user interaction.
2
What capabilities could successful exploitation provide?
A successful attacker could launch an arbitrary activity with Samsung Tips privilege.
3
Which versions are affected?
Samsung Tips versions prior to Android 17 are affected.