Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2024-34617MEDIUMImproper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default MessagEPSS 0.1%CVE-2024-34586MEDIUMImproper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.EPSS 0.1%CVE-2025-21019MEDIUMImproper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interactiEPSS 0.1%CVE-2025-21031MEDIUMImproper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.EPSS 0.1%CVE-2026-21006MEDIUMImproper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.EPSS 0.1%CVE-2021-25364MEDIUMA pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact EPSS 0.1%CVE-2023-30726MEDIUMPendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.EPSS 0.1%CVE-2025-21003MEDIUMInsecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive informEPSS 0.1%CVE-2023-30720MEDIUMPendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.EPSS 0.1%CVE-2023-30701MEDIUMPendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.EPSS 0.1%CVE-2025-20986MEDIUMImproper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots.EPSS 0.1%CVE-2025-20886MEDIUMInclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to getEPSS 0.1%CVE-2025-20970MEDIUMImproper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackeEPSS 0.1%CVE-2025-20978MEDIUMImproper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.EPSS 0.1%CVE-2022-39845MEDIUMImproper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitraryEPSS 0.1%CVE-2025-20974MEDIUMImproper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interactiEPSS 0.1%CVE-2025-20987MEDIUMImproper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.EPSS 0.1%CVE-2025-20984MEDIUMIncorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in SamsEPSS 0.1%CVE-2025-21049MEDIUMImproper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interactEPSS 0.1%CVE-2025-58476MEDIUMOut-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.EPSS 0.1%