Skip to content
Samsung reveals August 2026 security patch details - Here's what's new

Samsung reveals August 2026 security patch details - Here's what's new

Sammyfans August 4, 2026

Samsung kicks off August 2026 by revealing the details of its latest security patch for Galaxy devices. Ahead of the public release of new foldable phones , the company has detailed this month’s SMR for millions of Galaxy users. Samsung Mobile is releasing a maintenance release for major flagship models as part of the monthly Security Maintenance Release (SMR) process. This SMR package includes a total of 56 patches from Google and Samsung. Android Security Bulletin – August 2026 Samsung phones run the Android operating system at the core, so they get fixes from Google’s Android Bulletin as well. The company has categorized the improvements in different classes for better transparency. Android Security Bulletin – August 2026 The patch contains overall 38 security improvements , in which 8 are labeled “Critical” and 30 are labeled “High.” Additionally, Samsung already fixed one in updates, while 8 do not apply to Galaxy devices. Critical CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884 High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531 One UI Security Bulletin – August 2026 Beyond Android patches, Samsung also provides 18 One UI-specific improvements to Galaxy devices. These fixes are categorized in two different levels, including “High” and “Moderate,” that enhance the security of Galaxy devices. One UI Security Bulletin – August 2026 Along with Google patches, Samsung Mobile provides 18 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customers’ confidence in the security of Samsung Mobile devices. High SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. Note: Some of the SVE items may not be included in this package, in case these items were already included in a maintenance release. Some SVE items included in the Samsung Android Security Update cannot be disclosed at this time.

Samsung Mobile is releasing a maintenance release for major flagship models as part of the monthly Security Maintenance Release (SMR) process. This SMR package includes a total of 56 patches from Google and Samsung. Android Security Bulletin – August 2026 Samsung phones run the Android operating system at the core, so they get fixes from Google’s Android Bulletin as well. The company has categorized the improvements in different classes for better transparency. Android Security Bulletin – August 2026 The patch contains overall 38 security improvements , in which 8 are labeled “Critical” and 30 are labeled “High.” Additionally, Samsung already fixed one in updates, while 8 do not apply to Galaxy devices. Critical CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884 High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531 One UI Security Bulletin – August 2026 Beyond Android patches, Samsung also provides 18 One UI-specific improvements to Galaxy devices. These fixes are categorized in two different levels, including “High” and “Moderate,” that enhance the security of Galaxy devices. One UI Security Bulletin – August 2026 Along with Google patches, Samsung Mobile provides 18 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customers’ confidence in the security of Samsung Mobile devices. High SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. Note: Some of the SVE items may not be included in this package, in case these items were already included in a maintenance release. Some SVE items included in the Samsung Android Security Update cannot be disclosed at this time.

Samsung phones run the Android operating system at the core, so they get fixes from Google’s Android Bulletin as well. The company has categorized the improvements in different classes for better transparency. Android Security Bulletin – August 2026 The patch contains overall 38 security improvements , in which 8 are labeled “Critical” and 30 are labeled “High.” Additionally, Samsung already fixed one in updates, while 8 do not apply to Galaxy devices. Critical CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884 High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531 One UI Security Bulletin – August 2026 Beyond Android patches, Samsung also provides 18 One UI-specific improvements to Galaxy devices. These fixes are categorized in two different levels, including “High” and “Moderate,” that enhance the security of Galaxy devices. One UI Security Bulletin – August 2026 Along with Google patches, Samsung Mobile provides 18 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customers’ confidence in the security of Samsung Mobile devices. High SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. Note: Some of the SVE items may not be included in this package, in case these items were already included in a maintenance release. Some SVE items included in the Samsung Android Security Update cannot be disclosed at this time.

The patch contains overall 38 security improvements , in which 8 are labeled “Critical” and 30 are labeled “High.” Additionally, Samsung already fixed one in updates, while 8 do not apply to Galaxy devices. Critical CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884 High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

Critical CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884 High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884 High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

High CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084 CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665 CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885 Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

Moderate None Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

Already included in updates CVE-2026-0054 Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

Not applicable to Samsung devices CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531

Beyond Android patches, Samsung also provides 18 One UI-specific improvements to Galaxy devices. These fixes are categorized in two different levels, including “High” and “Moderate,” that enhance the security of Galaxy devices. One UI Security Bulletin – August 2026 Along with Google patches, Samsung Mobile provides 18 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customers’ confidence in the security of Samsung Mobile devices. High SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. Note: Some of the SVE items may not be included in this package, in case these items were already included in a maintenance release. Some SVE items included in the Samsung Android Security Update cannot be disclosed at this time.

Along with Google patches, Samsung Mobile provides 18 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customers’ confidence in the security of Samsung Mobile devices. High SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

High SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

SVE-2026-1829(CVE-2026-21064) Affected versions: Android 14, 15, 16 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

SVE-2026-1946(CVE-2026-21073) Affected versions: Android 14, 15, 16 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

Moderate SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

SVE-2025-2363(CVE-2026-21058) Affected versions: Android 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

SVE-2025-2364(CVE-2026-21059) Affected versions: Android 16 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts’ privilege. SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-2026-21062) Affected versions: Android 14, 15, 16 Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. SVE-2026-1053(CVE-2026-21071) Affected versions: Android 14, 15, 16 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-1498(CVE-2026-21063) Affected versions: Android 14, 15, 16 Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. SVE-2026-1813(CVE-2026-21072) Affected versions: Android 14, 15, 16 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2065(CVE-2026-21065) Affected versions: Android 14, 15, 16 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2068(CVE-2026-21066) Affected versions: Android 14, 15, 16 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2135(CVE-2026-21067) Affected versions: Android 14, 15, 16 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-2525(CVE-2026-21068) Affected versions: Android 14, 15, 16 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

SVE-2025-2365(CVE-2026-21060) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. SVE-2025-2545(CVE-2026-21061) Affected versions: Android 14, 15, 16 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability. SVE-2026-0615(CVE-2026-21069) Affected versions: Android 14, 15, 16 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. SVE-2026-0870(CVE-2026-21070) Affected versions: Android 14, 15 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. SVE-2026-0916(CVE-20...