CVE-2026-21052 Details
Description
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
A path traversal vulnerability has been identified in the SemClipboardService component of Samsung devices, affecting several different versions of Android. This vulnerability allows local privileged attackers to access files with system privileges. The issue arises from improper input validation, which creates an opportunity for unauthorized file access.
Users can apply the security update included in the Samsung July 2026 Security Maintenance Release to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Samsung Android | >= 14, < 15 >= 15, < 16 >= 16, < 17 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion