PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21036 Samsung Mobile CVE debrief

CVE-2026-21036 is a medium-severity vulnerability in Samsung Internet prior to version 30.0.0.39. The vulnerability is caused by improper authorization, allowing local attackers to access sensitive information. The CVE was published on 2026-06-05T11:16:36.310Z and last modified on 2026-06-05T14:59:51.620Z.

Vendor
Samsung Mobile
Product
Samsung Internet
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-05
Original CVE updated
2026-06-30
Advisory published
2026-06-05
Advisory updated
2026-06-30

Who should care

Users of Samsung Internet prior to version 30.0.0.39 should update to the latest version to mitigate this vulnerability.

Technical summary

The vulnerability has a CVSS score of 6.3 and is classified as MEDIUM severity. The CVSS vector is CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

The vulnerability is considered medium-severity and requires attention. Users should update to the latest version of Samsung Internet to mitigate this vulnerability.

Recommended defensive actions

  • Update to Samsung Internet version 30.0.0.39 or later.

Evidence notes

The vendor is listed as Unknown Vendor, but evidence suggests the vulnerability is related to Samsungmobile.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-21036 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-21036

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-21036 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21036

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.