CVE-2026-21112: Samsung Android
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
Affected products
- Samsung Android: before 17.0 (fixed in 17.0)
Published 2026-09-09. Last modified 2026-09-23.