Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with… (CVE-2026-21059)
CVE-2026-21059 is a vulnerability in Samsung Contacts prior to the SMR Aug-2026 Release 1 where improper export of Android application components allows local attackers to delete files with the app's privileges. This issue affects local attackers and does not require user interaction. The vulnerability has a medium severity rating.
AI Analysis
Technical Summary
This vulnerability involves improper export of Android application components in Samsung Contacts versions before SMR Aug-2026 Release 1. It enables local attackers to delete files with the privileges of the Samsung Contacts application. The CVSS 4.0 vector indicates local attack vector, low attack complexity, no privileges required, no user interaction, and high impact on integrity. No known exploits are reported in the wild, and no patch links or vendor advisories are provided in the data.
Potential Impact
Local attackers can delete files with the privileges of the Samsung Contacts application, potentially leading to data loss or disruption of application functionality. The impact is limited to local attackers and does not involve remote exploitation or privilege escalation beyond the app's existing permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor Samsung security advisories for updates related to SMR Aug-2026 Release 1. Until a fix is available, restricting local access to trusted users may reduce risk.
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with… (CVE-2026-21059)
Description
CVE-2026-21059 is a vulnerability in Samsung Contacts prior to the SMR Aug-2026 Release 1 where improper export of Android application components allows local attackers to delete files with the app's privileges. This issue affects local attackers and does not require user interaction. The vulnerability has a medium severity rating.
CVSS v4.0
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper export of Android application components in Samsung Contacts versions before SMR Aug-2026 Release 1. It enables local attackers to delete files with the privileges of the Samsung Contacts application. The CVSS 4.0 vector indicates local attack vector, low attack complexity, no privileges required, no user interaction, and high impact on integrity. No known exploits are reported in the wild, and no patch links or vendor advisories are provided in the data.
Potential Impact
Local attackers can delete files with the privileges of the Samsung Contacts application, potentially leading to data loss or disruption of application functionality. The impact is limited to local attackers and does not involve remote exploitation or privilege escalation beyond the app's existing permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor Samsung security advisories for updates related to SMR Aug-2026 Release 1. Until a fix is available, restricting local access to trusted users may reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pgp3-v5mx-qq76
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-21059"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a79f0e1bf8831d539f62d32
Added to database: 08/10/2026, 15:40:17 UTC
Last enriched: 08/10/2026, 16:04:31 UTC
Last updated: 08/11/2026, 03:40:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.