Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2023-21462MEDIUMThe sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 EPSS 0.2%CVE-2023-30711MEDIUMImproper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.EPSS 0.2%CVE-2023-30719MEDIUMExposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certaiEPSS 0.2%CVE-2025-20939MEDIUMImproper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update devEPSS 0.2%CVE-2023-30732MEDIUMImproper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.EPSS 0.2%CVE-2024-34672MEDIUMImproper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android EPSS 0.2%CVE-2023-21421MEDIUMImproper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allowsEPSS 0.2%CVE-2023-21429MEDIUMImproper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.EPSS 0.2%CVE-2024-20874HIGHImproper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activitiEPSS 0.2%CVE-2023-21460MEDIUMImproper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.EPSS 0.2%CVE-2026-21019HIGHImproper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code wEPSS 0.2%CVE-2022-27826HIGHImproper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.2%CVE-2023-21432MEDIUMImproper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the ownEPSS 0.2%CVE-2026-21018MEDIUMOut-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.EPSS 0.2%CVE-2024-20859MEDIUMImproper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without priviEPSS 0.2%CVE-2023-30665MEDIUMImproper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause anEPSS 0.2%CVE-2024-20802MEDIUMImproper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification inEPSS 0.2%CVE-2024-34678MEDIUMOut-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.EPSS 0.2%CVE-2024-34676MEDIUMOut-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory coEPSS 0.2%CVE-2025-21032MEDIUMImproper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditioEPSS 0.2%