Samsung Tips Improper Input Validation Allows Local Activity Launch (Android 17)
CVE-2026-21112 Published on September 9, 2026

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.

NVD

Vulnerability Analysis

CVE-2026-21112 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
PASSIVE

Affected Versions

Samsung Mobile Samsung Tips: