Samsung LocationManager Privilege Escalation Vulnerability Allowing Access to Sensitive Information

Vulnerability

A vulnerability exists in the LocationManager component of Samsung devices running Android versions 14, 15, and 16, prior to the May 2026 Security Maintenance Release. This vulnerability allows local attackers to access sensitive information due to incorrect privilege assignment. The issue arises from improper validation logic, which has been addressed in the latest security update.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information.

Remediation

Users can apply the May 2026 Security Maintenance Release to address this vulnerability. This update is part of the regular monthly security update process and includes patches from both Google and Samsung.

Added: May 13, 2026, 4:43 PM
Updated: May 13, 2026, 4:43 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.