Samsung has patched four vulnerabilities in its Smart Switch Android app that could expose sensitive data or allow adjacent attackers to impersonate a device.
The flaws affect Samsung Smart Switch for Android versions earlier than 3.7.72.6, according to Samsung’s August security bulletin. Three could expose or provide access to sensitive data, while another could allow an attacker to spoof a device’s identity.
That matters because Smart Switch can handle a wide range of personal data when users move to a new Galaxy device, including contacts, messages, photos, videos, documents, account information and device settings.
Four Smart Switch flaws fixed in latest version
One of the two High-severity issues, CVE-2026-21079, stems from the absence of encryption for sensitive data transmitted by Smart Switch.
Samsung said the vulnerability could allow an adjacent attacker to intercept transmitted information on versions before 3.7.72.6. The company said the patch adds proper encryption logic.
The National Vulnerability Database assigns the flaw a CVSS 3.1 score of 6.5 (Medium), while Samsung’s CVSS 4.0 assessment rates it 7.0 (High).
A second High-severity vulnerability, CVE-2026-21080, involves Smart Switch storing sensitive information in cleartext. Samsung said an adjacent attacker could potentially access that information. The update removes the exposure.
Two additional vulnerabilities are rated Moderate.
CVE-2026-21078 involves insufficient verification in Smart Switch’s trouble-scanning mode, potentially allowing an adjacent attacker to spoof a device’s identity. CVE-2026-21083 involves improper input validation that Samsung said could allow an adjacent attacker to access sensitive data.
Samsung credited researchers Rene Denifl and Florian Draschbacher with reporting all four vulnerabilities.
The Smart Switch fixes arrive alongside a broader Samsung security push. Earlier this month, Samsung’s August Galaxy update addressed 56 vulnerabilities across eligible Galaxy devices, including eight Android flaws rated critical.
Why Smart Switch makes sensitive data especially important
Smart Switch is designed specifically to move data between devices, which makes weaknesses involving encryption, authentication and information exposure particularly noteworthy.
According to Samsung’s support documentation, the app can transfer content from Android and iOS devices to Galaxy phones and tablets through wireless connections, USB cables or external storage.
Depending on the devices involved, the information transferred can include contacts, call logs, messages, photos, videos, documents, settings, and account data.
These flaws are not described as internet-wide remote vulnerabilities. Samsung classifies the attack vectors for all four as adjacent, meaning an attacker would need access through an adjacent network or connection context rather than simply reaching a vulnerable device remotely from anywhere online.
NVD’s entry for CVE-2026-21079 also cites a CISA assessment listing exploitation as “none” as of Aug. 10. That assessment applies specifically to CVE-2026-21079 and should not be interpreted as an exploitation assessment for all four Smart Switch vulnerabilities.
Still, mobile devices continue to attract attacks aimed at extracting sensitive information. eSecurity Planet recently reported on Manic Android malware capable of stealing passwords, one-time codes, and other information, then relaying the stolen data to nearby compromised phones.
Smart Switch had serious flaws earlier this year
The latest fixes are not Samsung’s first Smart Switch for Android security patches of 2026.
Samsung’s March bulletin disclosed a set of Smart Switch vulnerabilities affecting versions before 3.7.69.15. Five CVEs tied to one critical authentication weakness could allow remote attackers to install arbitrary applications, according to Samsung.
Another High-severity flaw involved path traversal that could allow an adjacent attacker to overwrite arbitrary files with Smart Switch privileges. Samsung also patched an authentication vulnerability that could allow an adjacent attacker to trigger a denial-of-service condition.
The recurring fixes illustrate why application updates matter even when the underlying Galaxy operating system is fully patched.
Other smartphone makers are dealing with the same broader challenge. Apple recently released an update addressing critical iPhone security flaws that could lead to malicious code execution and other security consequences.
What Samsung users should do now
Android users using Samsung Smart Switch should ensure the app is version 3.7.72.6 or later. Samsung lists 3.7.72.6 as the resolved Android app version for all four vulnerabilities.
Galaxy users can check for Smart Switch updates through the Galaxy Store or Google Play. Organizations managing Galaxy phones should also verify application versions on corporate devices rather than assuming an operating system update has patched every Samsung application.
Samsung’s August advisory does not state that the four Smart Switch vulnerabilities are being actively exploited.
The attack requirements lower the immediate alarm level compared with remotely exploitable vulnerabilities, but the type of data Smart Switch handles still makes updating worthwhile. If an app is trusted to carry a user’s contacts, messages, photos, accounts and settings from one phone to another, keeping that transfer channel patched should be part of the move.
Also read: Samsung Galaxy users have faced more serious mobile threats, including the LANDFALL spyware campaign that exploited a zero-day vulnerability to target Galaxy devices.





