CVE-2026-21092
massPath Traversal in Samsung ImsService Allows System-Privilege File Creation
Samsung's ImsService, the system component that handles IP Multimedia Subsystem (VoLTE/VoWiFi) traffic on Galaxy devices, contains a path traversal flaw. A remote attacker can trigger it by sending crafted data over the network interface used by ImsService, causing the service to write image files to unintended filesystem locations. The attacker gains the ability to create image files with system server privileges, yielding a high integrity impact and a low confidentiality impact (CVSS 4.0: 8.8). Any Samsung mobile device running a software state prior to the SMR Sep-2026 Release 1 security maintenance release is affected. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Install the Samsung SMR Sep-2026 Release 1 security update via Settings > Software update (or push it through MDM for managed fleets) and verify devices report a security patch level of September 2026 or later. No public PoC or known exploitation exists yet, so the near-term risk is low, but unpatched devices should be updated promptly. There is no described mitigation other than applying the patch.
| Samsung ImsService (preloaded on Samsung Galaxy mobile devices) | all software states prior to SMR Sep-2026 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-35
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.