Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2022-33733MEDIUMSensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connectioEPSS 0.2%CVE-2025-21047MEDIUMImproper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.EPSS 0.2%CVE-2023-30657MEDIUMImproper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privilEPSS 0.2%CVE-2023-30659MEDIUMImproper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activitieEPSS 0.2%CVE-2023-21453MEDIUMImproper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.EPSS 0.2%CVE-2023-30722MEDIUMProtection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute EPSS 0.2%CVE-2024-20841MEDIUMImproper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.EPSS 0.2%CVE-2022-36867MEDIUMImproper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.EPSS 0.2%CVE-2023-21511MEDIUMOut-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore priorEPSS 0.2%CVE-2021-25407A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.EPSS 0.2%CVE-2023-21500MEDIUMDouble free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to accesEPSS 0.2%CVE-2023-21510MEDIUMOut-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to versEPSS 0.2%CVE-2023-21507MEDIUMOut-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain KeyEPSS 0.2%CVE-2023-42579MEDIUMImproper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49,EPSS 0.2%CVE-2025-21065MEDIUMImproper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.EPSS 0.2%CVE-2024-20886MEDIUMArbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.EPSS 0.2%CVE-2022-39876MEDIUMInsertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.EPSS 0.2%CVE-2022-36829MEDIUMPendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files withEPSS 0.2%CVE-2022-36830MEDIUMPendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access fileEPSS 0.2%CVE-2024-20824MEDIUMImplicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive EPSS 0.2%