VYPR
Low severity2.8NVD Advisory· Published Apr 13, 2026· Updated Apr 16, 2026

CVE-2026-21014

CVE-2026-21014

Description

Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Samsung Camera prior to 16.5.00.28 lets a local attacker access location data with user interaction.

Vulnerability

Overview

CVE-2026-21014 is an improper access control vulnerability in the Samsung Camera application. The flaw exists in versions prior to 16.5.00.28, where the app fails to properly enforce permissions, allowing a local attacker to access sensitive location data. The root cause is a missing or insufficient access control check that should restrict location information to authorized processes or user interactions.

Exploitation

Conditions

Exploitation requires local access to the device and user interaction. The attacker must be able to run code on the same device (e.g., through a malicious app or physical access) and convince the user to perform an action that triggers the vulnerability. No network-based attack vector is involved; the attack surface is limited to the local environment.

Impact

A successful exploit allows the attacker to read the device's location data, which could reveal the user's whereabouts. This information could be used for surveillance or other privacy-invasive purposes. The CVSS v3 base score of 2.8 reflects the low severity due to the need for local access and user interaction.

Mitigation

Samsung has addressed the issue in Camera version 16.5.00.28 and later. Users are advised to update the application through the Galaxy Store or Samsung's update mechanism. The official advisory is available on the Samsung Mobile Security portal [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*range: <16.5.00.28
    • (no CPE)range: <16.5.00.28

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.