SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-21034

Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

MEDIUM 4.8EPSS 0.08%

Does this matter?

Lower severity and a low EPSS score (0.08%). Track it; it rarely justifies an emergency change on its own.

Description

Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

CVSS 4.0
4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Affected
samsung/auto
Source
mobile.security@samsung.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.