CVE-2026-21020 is an improper export of Android application components vulnerability in Samsung OmaCP prior to SMR May-2026 Release 1. The flaw allows application components to be exposed more broadly than intended, enabling a local attacker to invoke privileged functionality through those exported components without the intended access restrictions. In affected configurations, this can result in unauthorized access to privileged operations exposed by the OmaCP application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small repository containing a single Python proof-of-concept script, a README, and a license. The main file, proto_vuln.py, demonstrates insecure handling of Protocol Buffers Any messages by assigning an attacker-controlled type_url (type.googleapis.com/attacker.Evil) and serialized value bytes, then attempting to validate/unpack against addressbook_pb2.Person. The code does not perform exploitation against a live target and contains no networking logic; instead, it models a vulnerable application pattern where dynamic loading or trust in Any.type_url could cause type confusion, logic flaws, privilege escalation, or possible RCE in real systems. Repository structure is minimal: README explains the claimed CVE-2026-21020 scenario and execution steps, while the Python script serves as the sole entry point and demonstration artifact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.