CVE-2026-21057: Input Validation
Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Passto a version that resolves this vulnerability.Fixed in 5.2.10.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21057?
CVE-2026-21057 has a medium severity rating of 6.8 according to the CVSS v3.1 scoring system.
How do I fix CVE-2026-21057?
To mitigate CVE-2026-21057, update Samsung Pass to version 5.2.10.3 or later.
What is the cause of CVE-2026-21057?
CVE-2026-21057 is caused by improper input validation that allows local privileged attackers to write out-of-bounds memory.
Who is affected by CVE-2026-21057?
Users of Samsung Pass prior to version 5.2.10.3 are affected by CVE-2026-21057.
What types of attacks can exploit CVE-2026-21057?
CVE-2026-21057 can be exploited by local privileged attackers to manipulate memory, potentially leading to unstable application behavior.