nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-21075 CVE-2026-21075
MEDIUM
Samsung My Galaxy Custom URL Scheme Improper Authorization
Record summary
CVE-2026-21075 has a selected CVSS score of 5.3 (medium).
Description
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
My GalaxyBrowse Samsung Mobile / My GalaxyDefault status: affected | CVE List | 6.3 to < * | unaffected |
References
2security.samsungmobile.com
https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=08