CVE-2026-21057: Samsung Mobile Samsung Pass
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
Affected products
- Samsung Mobile Samsung Pass: before 5.2.10.3 (fixed in 5.2.10.3)
Published 2026-07-10. Last modified 2026-07-10.