Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2024-34671LOWUse of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to geEPSS 0.2%CVE-2023-30691HIGHParcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.EPSS 0.2%CVE-2024-20810LOWImplicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive informaEPSS 0.2%CVE-2023-30724MEDIUMImproper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search history.EPSS 0.2%CVE-2021-25391MEDIUMIntent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.EPSS 0.2%CVE-2026-21003MEDIUMImproper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the reEPSS 0.2%CVE-2022-33730MEDIUMHeap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical aEPSS 0.2%CVE-2026-21007MEDIUMImproper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.EPSS 0.2%CVE-2025-20931HIGHOut-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.EPSS 0.2%CVE-2023-30648LOWStack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the EPSS 0.2%CVE-2025-21073MEDIUMInsecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user daEPSS 0.2%CVE-2024-34643MEDIUMImproper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protecteEPSS 0.2%CVE-2024-20842MEDIUMImproper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to EPSS 0.2%CVE-2023-30725MEDIUMImproper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.EPSS 0.2%CVE-2021-25450MEDIUMPath traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remEPSS 0.2%CVE-2025-21048MEDIUMRelative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.EPSS 0.2%CVE-2023-42539MEDIUMPendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to acceEPSS 0.2%CVE-2024-20848MEDIUMImproper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attaEPSS 0.2%CVE-2023-30738MEDIUMAn improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360EPSS 0.2%CVE-2023-52432MEDIUMImproper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-boEPSS 0.2%