Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2021-25461MEDIUMAn improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.EPSS 0.2%CVE-2026-20990HIGHImproper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrarEPSS 0.2%CVE-2022-39857HIGHImproper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcastiEPSS 0.2%CVE-2026-20968MEDIUMUse after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.EPSS 0.2%CVE-2025-20882HIGHOut-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to eEPSS 0.2%CVE-2023-30707MEDIUMImproper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attacEPSS 0.2%CVE-2021-25429Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to accessEPSS 0.2%CVE-2025-20881HIGHOut-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackEPSS 0.2%CVE-2024-20893MEDIUMImproper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruptionEPSS 0.2%CVE-2023-30654MEDIUMImproper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.EPSS 0.2%CVE-2021-25430Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the BEPSS 0.2%CVE-2025-21063MEDIUMImproper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attEPSS 0.2%CVE-2024-20836LOWOut of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out oEPSS 0.2%CVE-2021-25390MEDIUMIntent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.EPSS 0.2%CVE-2023-21426MEDIUMHardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.EPSS 0.2%CVE-2023-30709HIGHImproper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.EPSS 0.2%CVE-2022-39878MEDIUMImproper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via impEPSS 0.2%CVE-2025-20956MEDIUMImproper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to aEPSS 0.2%CVE-2024-49404MEDIUMImproper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android EPSS 0.2%CVE-2023-30671MEDIUMLogic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed applicatioEPSS 0.2%