In short: Samsung released its monthly security bulletin for August 2026, closing 56 vulnerabilities in Galaxy devices — 8 of them rated critical. The critical CVEs affect Android kernel components and allow remote code execution or privilege escalation without user interaction. At the One UI layer the patch fixes an authorization bypass in the clipboard service, memory-safety issues in video codecs, and input-validation flaws in Contacts, Messages and Phone apps. If you own a Galaxy S23–S26, Z Fold/Flip 8 or any Galaxy A-series device, this is the update to install today.
What happened
On 4–5 August 2026 Samsung published its monthly Security Maintenance Release, SMR-AUG-2026. The package covers 56 fixes: 38 drawn from Google's August Android Security Bulletin and 18 Samsung-specific SVE patches. Compared to July the number of critical-severity issues rose from five to eight. Detailed coverage was published by Comss.ru and Notebookcheck. For a broader look at layered security practices, see our security blog.
Critical vulnerabilities: what is at risk
Eight critical CVEs target Android kernel components. Successful exploitation can allow an attacker to execute arbitrary code or elevate privileges to system level without any tap from the user — by sending a crafted message or triggering a media decode, depending on the specific CVE. The identifiers are CVE-2026-25289, CVE-2026-28591, CVE-2026-28653, CVE-2026-28662, CVE-2026-45515, CVE-2026-49879, CVE-2026-49882, and CVE-2026-49884.
At the One UI layer, Samsung addressed several component-specific issues:
- SemClipboardService (SVE-2026-0916) — authorization bypass on clipboard access. A malicious app could silently read clipboard contents, including passwords and one-time codes.
- VC1 and MPEG4 codecs (libsavsvc.so) — out-of-bounds memory access when processing video files. A crafted media file could cause a crash or, in a worst case, code execution.
- Weaver hardware module (SVE-2026-1829) — access-control flaw in the device's secure storage subsystem.
- Contacts, Phone, Messages, Galaxy Themes and AppLock — input-validation weaknesses that could lead to information disclosure or denial of service.
Which devices are affected
Samsung distributes patches in waves throughout the month. Flagships receive the update first: Galaxy Z Fold 8, Z Flip 8 and the Galaxy S26 series, followed by Galaxy S23–S25, Galaxy A54, A57, Tab Active5 Pro and the rugged XCover 6/7. The update arrives as an OTA firmware push — no action is required beyond tapping "Install" when prompted.
What this means for your data
The clipboard bypass in SemClipboardService is the most privacy-sensitive issue in this release. The clipboard is a silent transit point for some of the most sensitive data you handle: a password copied from a manager, a one-time SMS code, payment details from an email. If a third-party app can read it without permission, every paste becomes a potential data-exposure event.
The codec vulnerabilities are a reminder that attacks do not always require a link click or an app install. A crafted video file sent via a messenger and auto-played by the gallery could, in the worst case, lead to code execution — a vector requiring no interaction at all. On LiMP VPN's features page you can see how network-level encryption complements this kind of device-level protection.
How to protect yourself
Update your Galaxy now: go to Settings → Software Update → Download and Install. If the August 2026 bulletin is available, install it immediately. If the prompt has not appeared yet, Samsung is still rolling it out — check daily.
Audit clipboard permissions. Until the patch is installed, review which apps have clipboard access: Settings → Privacy → Permission Manager → Clipboard. Revoke access for any app that has no legitimate need for it.
Add a network layer. Device updates close vulnerabilities in the software itself but do not encrypt your traffic in transit. LiMP VPN encrypts everything your Galaxy sends over the network — particularly important on public Wi-Fi, where traffic can be intercepted before it leaves the building.
