Samsung Cloud Assistant <9.0.5 Intent Mis-Verification Allows Local Disable
CVE-2026-21106 Published on September 9, 2026

Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

NVD

Vulnerability Analysis

CVE-2026-21106 is exploitable with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Products Associated with CVE-2026-21106

Want to know whenever a new CVE is published for Samsung Cloud? stack.watch will email you.

 

Affected Versions

Samsung Mobile Samsung Cloud Assistant: