Samsung Tips Improper Input Validation Allows Local Activity Launch (Android 17)
CVE-2026-21112 Published on September 9, 2026
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
Vulnerability Analysis
CVE-2026-21112 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
PASSIVE
Affected Versions
Samsung Mobile Samsung Tips:- Version Android 17 and below * is unaffected.