Samsung Mobile is releasing a maintenance release for major flagship models as part of monthly Security Maintenance Release (SMR) process. This SMR package includes patches from Google and Samsung.
Google Patches for the following CVEs from Android Security Bulletin are applied in this Security Maintenance Release - August 2026 Package.
Critical
CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884
High
CVE-2025-22442, CVE-2026-0022, CVE-2026-20473, CVE-2026-20474, CVE-2026-20475, CVE-2026-20477, CVE-2026-20479, CVE-2026-20481, CVE-2026-20497, CVE-2026-24084, CVE-2026-28611, CVE-2026-28620, CVE-2026-28645, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28665, CVE-2026-28667, CVE-2026-45513, CVE-2026-45518, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49885
Moderate
None
Already included in previous updates
CVE-2026-0054
Not applicable to Samsung devices
CVE-2026-20464, CVE-2026-20467, CVE-2026-20468, CVE-2026-20469, CVE-2026-24079, CVE-2026-24080, CVE-2026-25288, CVE-2026-45531
※ Please see Android Security Bulletin for detailed information on Google patches.
Along with Google patches, Samsung Mobile provides 18 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customer’s confidence on security of Samsung Mobile devices. Samsung security index (SSI), found in “Security software version”, SMR Aug-2026 Release 1 includes all patches from Samsung and Google. Some of the SVE items may not be included in this package, in case these items were already included in a previous maintenance release.
High
SVE-2026-1829(CVE-2026-21064)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
The patch adds proper access control checks.
SVE-2026-1946(CVE-2026-21073)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
The patch adds proper input validation.
Moderate
SVE-2025-2363(CVE-2026-21058)
Affected versions: Android 16
Disclosure status: Privately disclosed
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
The patch adds proper input validation.
SVE-2025-2364(CVE-2026-21059)
Affected versions: Android 16
Disclosure status: Privately disclosed
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
The patch adds proper access control.
SVE-2025-2365(CVE-2026-21060)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
The patch adds proper input validation.
SVE-2025-2545(CVE-2026-21061)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related function. User interaction is required for triggering this vulnerability.
The patch removes unnecessary implementation.
SVE-2026-0615(CVE-2026-21069)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-0870(CVE-2026-21070)
Affected versions: Android 14, 15
Disclosure status: Privately disclosed
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
The patch adds proper input validation.
SVE-2026-0916(CVE-2026-21062)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
The patch adds proper authorization.
SVE-2026-1053(CVE-2026-21071)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-1498(CVE-2026-21063)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
The patch adds proper access control.
SVE-2026-1813(CVE-2026-21072)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-2065(CVE-2026-21065)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper validation logic.
SVE-2026-2068(CVE-2026-21066)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-2135(CVE-2026-21067)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-2525(CVE-2026-21068)
Affected versions: Android 14, 15, 16
Disclosure status: Privately disclosed
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
The patch adds proper input validation.
Some SVE items included in the Samsung Android Security Update cannot be disclosed at this time.
Acknowledgements
develicit: SVE-2026-1829
Dawuge of Shuffle Team: SVE-2025-2363, SVE-2025-2364, SVE-2025-2365
Chen Jiang of vivo kM1rr0rs secLab: SVE-2025-2545
suhyeon.jin: SVE-2026-0615
Bob Lam: SVE-2026-0870
Tianyi Hu: SVE-2026-0916
Viktor Babkov: SVE-2026-1053
moyu: SVE-2026-1498
Ye Zhang (@VAR10CK) of Baidu Security: SVE-2026-1813, SVE-2026-2065, SVE-2026-2068
Calif.io in collaboration with Claude and Anthropic Research: SVE-2026-2135
YeonghyeonChoi: SVE-2026-2525
Version
| Version | Date | Notes |
|---|
| 1.0 | Aug 4, 2026 | Bulletin published |