CVE-2026-21077 is an authorization flaw in Samsung Health that allows any app on the device — or any secondary user with local access — to read health data without the user's consent. Version 7.0.0 contains the fix; earlier versions are vulnerable. If you're running Samsung Health below 7.0.0, treat this as active exposure.

The CVSS 6.9 rating is inadequate and here's why: it treats health data like contacts, but cardiac rhythms, sleep records, and reproductive health metrics have what amounts to permanent future exposure — they're medically meaningful and personally embarrassing indefinitely. The CVSS framework has no mechanism to score this. That alone should elevate your prioritization beyond what the number suggests.

More importantly, the 'local attacker' framing is dangerously narrow. This includes any malicious app that lands on the device through a separate vulnerability, any compromised companion app with limited permissions, or a stolen device with screen lock bypass. Samsung Health runs as a privileged system app with Knox integration — this flaw becomes the privilege escalation bridge that takes a partial compromise and delivers full health data access. For an attacker who doesn't already control Knox, this authorization check is the key that unlocks everything Samsung's security model was supposed to compartmentalize.

The architectural nature of the 7.0.0 fix matters. Samsung shipped a major version bump rather than a point release, which signals the authorization failure was embedded in the trust model itself rather than a single missed check. This means the vulnerable code path likely still exists in the binary — now gated behind new guards rather than removed. Assess whether 7.0.0 truly eliminates the exposure or merely layers controls over flawed assumptions.

Samsung's Android fragmentation is the compounding variable. Version 7.0.0 is not yet universal across Galaxy devices, particularly older S-series and A-series hardware. Devices still running 6.x represent a population under active exposure with no realistic recourse — they cannot accelerate their update timeline, and Samsung's security disclosure practices historically lack proactive user notification. Check your Samsung Health version now; if you're below 7.0.0, update immediately and monitor for unauthorized data access indicators. If you're responsible for fleet security, treat Samsung Health on pre-7.0.0 devices as a known data exposure vector in your threat model.