Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2022-36830MEDIUMPendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access fileEPSS 0.2%CVE-2024-20825MEDIUMImplicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive informatEPSS 0.2%CVE-2021-25410Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files wiEPSS 0.2%CVE-2024-20822MEDIUMImplicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitEPSS 0.2%CVE-2022-36829MEDIUMPendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files withEPSS 0.2%CVE-2023-21457MEDIUMImproper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without relatEPSS 0.2%CVE-2023-21449MEDIUMImproper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive informaEPSS 0.2%CVE-2026-20996HIGHUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgradeEPSS 0.2%CVE-2023-30733HIGHStack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform codeEPSS 0.2%CVE-2023-30680HIGHImproper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.EPSS 0.2%CVE-2022-36870MEDIUMPending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global aEPSS 0.2%CVE-2021-25361HIGHAn improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary EPSS 0.2%CVE-2023-30734MEDIUMImproper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via impEPSS 0.2%CVE-2023-30710HIGHImproper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.EPSS 0.2%CVE-2023-30697MEDIUMAn improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounEPSS 0.2%CVE-2024-20868MEDIUMImproper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege underEPSS 0.2%CVE-2022-36833HIGHImproper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 EPSS 0.2%CVE-2023-30658HIGHImproper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activitieEPSS 0.2%CVE-2023-30737MEDIUMImproper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via impEPSS 0.2%CVE-2023-30664HIGHImproper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged actiEPSS 0.2%