Package
com.wsomacp
Configuration message
Guidance
Labelled "Configuration message" on every device in this sample, this is the Samsung component that receives and applies OMA CP messages. OMA CP is Open Mobile Alliance Client Provisioning, an industry standard for deploying network settings to mobile devices over the air; Check Point's research write up dates the standard to 2001 with its latest specification in 2009, and describes the messages as arriving over WAP Push, a binary SMS delivered to port 2948. The same write up sets out what such a message can change: MMS servers, proxy addresses, browser homepage and bookmarks, mail servers and directory servers for contact and calendar synchronisation. It has no launcher entry in any observation here, so nothing a user opens; it acts on messages the network sends. The permissions it declares, as recorded on this site, line up with that description rather than adding to it: RECEIVE_WAP_PUSH and BROADCAST_WAP_PUSH, RECEIVE_SMS, WRITE_APN_SETTINGS, and Samsung-defined permissions for the browser homepage and bookmarks and for the Samsung email provider. It is signed by a Samsung OEM key that also signs the Android framework. Its security history is the reason it is worth knowing about. Check Point reported in 2019 that Samsung devices accepted unauthenticated OMA CP messages, so an attacker who could send one needed only the user's acceptance to point the device at a proxy of their choosing. Samsung's own security bulletin records the fix as SVE-2019-14073, "Potential Phishing Flow in OMACP", in the Security Maintenance Release for May 2019, described there as a vulnerability allowing a manipulated OMACP message to change the network and internet settings on the device. So Samsung reported the issue fixed in May 2019; nothing here establishes that every device in the field received that release, and older or unpatched builds may remain affected. Either way, the point that carries forward is that this package is the component through which operator-pushed network configuration reaches the device. Version note: Samsung's own Common Criteria application lists record the same package under the same label on the Galaxy Note9 (the Oreo-era N960N list, at 7.1.13) and the Galaxy S20 (the R-era G981U list, at 7.4.07). Devices on this site report versions 7.5.02 to 9.2.08, observed from API 28 through API 37 and targeting API 30 to 36, and only on Samsung hardware. It is therefore long-standing and still maintained. Beyond the 2019 authentication fix, no source establishes a change in its role across Android releases, and none is implied by the data here. For Android Enterprise, EMM and kiosk use, the relevance is that this is the on-device path by which APN and proxy settings can be altered from outside the management channel, which is usually the configuration an administrator has deliberately fixed. The documented controls sit in policy rather than in the package: the Android Management API exposes mobileNetworksConfigDisabled, "Whether configuring mobile networks is disabled", and smsDisabled, "Whether sending and receiving SMS messages is disabled". Where the package itself needs to go, Samsung documents blocking a named preinstalled system app through Knox Manage's application policies rather than stripping it. The rating below is caution rather than safe because on a device that still depends on the operator to push its APN or MMS settings, removing the component that applies them can leave data or messaging misconfigured; on a fixed-configuration kiosk where the EMM supplies the APN, there is much less to lose. Test on one device before applying it to a fleet.
- Advanced SMS Phishing Attacks Against Modern Android-based Smartphones - Check Point Research →
- Samsung Security Maintenance Release, May 2019 (SVE-2019-14073, Potential Phishing Flow in OMACP) →
- Galaxy Note9 (N960N) application list - Samsung Knox CC Mode documentation →
- Galaxy S20 5G (G981U) application list - Samsung Knox CC Mode documentation →
- Policy resource reference (mobileNetworksConfigDisabled, smsDisabled) - Android Management API →
- Enable or disable a specific system app - Knox Manage - Samsung Knox Documentation →
- Package provenance for com.wsomacp - Android System App Database →
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, but 2 different certificates appear across the fleet, so OEMs ship their own builds of it. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 19 permissions: 4 runtime (user-granted), 4 signature or system-level, 4 install-time and 7 vendor or uncatalogued.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (19)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
BROADCAST_WAP_PUSH |
Signature-level system permission, for platform-signed apps. |
POST_NOTIFICATIONS |
Allows the app to show notifications |
READ_PHONE_STATE |
Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. |
READ_PRIVILEGED_PHONE_STATE |
Signature or privileged system permission. docs ↗ |
REAL_GET_TASKS |
Signature or privileged system permission. |
RECEIVE_SMS |
Allows the app to receive and process SMS messages. This means the app could monitor or delete messages sent to your device without showing them to you. |
RECEIVE_WAP_PUSH |
Allows the app to receive and process WAP messages. This permission includes the ability to monitor or delete messages sent to you without showing them to you. |
USE_FULL_SCREEN_INTENT |
Allows the app to display notifications as full screen activities on a locked device |
VIBRATE |
Allows the app to control the vibrator. |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WRITE_APN_SETTINGS |
Signature or privileged system permission. docs ↗ |
com.samsung.android.email.permission.ACCESS_PROVIDER |
- |
com.sec.android.app.browser.permission.Bookmark |
- |
com.sec.android.app.browser.permission.HOMEPAGE |
- |
com.sec.android.fotaclient.permission.FOTA |
- |
com.sec.epdg.PERMISSION |
- |
com.sec.imsservice.PERMISSION |
- |
com.sec.imsservice.permission.EPDG_NAME |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A057G | Android 15 | OEM Samsung | 1 | 8 Aug 2026 |
| Samsung | SM-A125F | Android 12 | OEM Samsung | 1 | 21 Jan 2026 |
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A515F | Android 13 | - | 1 | 30 Jun 2025 |
| Samsung | SM-A528B | Android 13 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G780F | Android 13 | OEM Samsung | 1 | 29 Dec 2025 |
| Samsung | SM-G973U | Android 12 | OEM Samsung | 2 | 10 Jun 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-M315F | Android 12 | - | 1 | 2 Feb 2026 |
| Samsung | SM-N950U1 | Android 9.0 | - | 1 | 20 Aug 2025 |
| Samsung | SM-N986B | Android 13 | - | 9 | 17 Jul 2025 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| Configuration message | en-gb | 24 |
| Configuration message | en | 18 |
| Configuration message | en-us | 17 |
| Configuratiebericht | nl-nl | 5 |
| Messaggio di configurazione | it-IT | 5 |
| Configuration message | en-nl | 3 |
| Konfigurationsnachricht | de-de | 3 |
| Configuration message | en-GB | 2 |
| Configuration message | 2 | |
| Mensaje de configuración | es-ES | 2 |
| Mensaje de configuración | es-es | 2 |
| Mensaje de configuración | es-us | 2 |
| Message de configuration | fr-fr | 2 |
| Messaggio di configurazione | it-it | 2 |
| Configuration message | en-au | 1 |
| Configuration message | en-US | 1 |
| Konfigurační zpráva | cs-cz | 1 |
| Konfigurační zpráva | cs-CZ | 1 |
| Mensaje de configuración | es-US | 1 |
| Message de configuration | fr-FR | 1 |
| Message de configuration | fr-dz | 1 |
| Wiadomość konfiguracyjna | pl-PL | 1 |
| Wiadomość konfiguracyjna | pl-pl | 1 |
| Сообщение конфигурации | ru-ru | 1 |