Samsung Cloud Assistant <9.0.5 Intent Mis-Verification Allows Local Disable
CVE-2026-21106 Published on September 9, 2026
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Vulnerability Analysis
CVE-2026-21106 is exploitable with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Products Associated with CVE-2026-21106
Want to know whenever a new CVE is published for Samsung Cloud? stack.watch will email you.
Affected Versions
Samsung Mobile Samsung Cloud Assistant:- Version 9.0.5 and below * is unaffected.