ZeroHour

CVE-2026-21092

mass

Path Traversal in Samsung ImsService Allows System-Privilege File Creation

CVSS 4.0
8.8 high
EPSS
<1%p34
Published
()
Modified
AI analysis

Samsung's ImsService, the system component that handles IP Multimedia Subsystem (VoLTE/VoWiFi) traffic on Galaxy devices, contains a path traversal flaw. A remote attacker can trigger it by sending crafted data over the network interface used by ImsService, causing the service to write image files to unintended filesystem locations. The attacker gains the ability to create image files with system server privileges, yielding a high integrity impact and a low confidentiality impact (CVSS 4.0: 8.8). Any Samsung mobile device running a software state prior to the SMR Sep-2026 Release 1 security maintenance release is affected. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Install the Samsung SMR Sep-2026 Release 1 security update via Settings > Software update (or push it through MDM for managed fleets) and verify devices report a security patch level of September 2026 or later. No public PoC or known exploitation exists yet, so the near-term risk is low, but unpatched devices should be updated promptly. There is no described mitigation other than applying the patch.

Affected
Samsung ImsService (preloaded on Samsung Galaxy mobile devices)all software states prior to SMR Sep-2026 Release 1
Estimated exposure
masshundreds of millions to over 1 billion Samsung Galaxy devices (ImsService ships as a preloaded system service on essentially all Samsung Android smartphones… — ImsService is a built-in component on virtually all Samsung Galaxy Android devices, and Samsung's global smartphone share (~20%) and annual shipment volumes put the installed base in the hundreds of millions to billions, though actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

Vendors
samsung
Products
android
Weakness
CWE-35
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.