Vulnerabilities in Samsung Mobile

1,391 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2026-21008MEDIUMExposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.EPSS 0.2%CVE-2024-34671LOWUse of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to geEPSS 0.2%CVE-2021-25391MEDIUMIntent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.EPSS 0.2%CVE-2023-30675MEDIUMImproper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung WaEPSS 0.2%CVE-2024-20810LOWImplicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive informaEPSS 0.2%CVE-2026-21007MEDIUMImproper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.EPSS 0.2%CVE-2026-21003MEDIUMImproper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the reEPSS 0.2%CVE-2026-21052MEDIUMPath traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilegEPSS 0.2%CVE-2022-39872MEDIUMImproper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.EPSS 0.2%CVE-2022-27826HIGHImproper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.EPSS 0.2%CVE-2026-20976MEDIUMImproper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.EPSS 0.2%CVE-2024-20848MEDIUMImproper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attaEPSS 0.2%CVE-2024-34643MEDIUMImproper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protecteEPSS 0.2%CVE-2023-30738MEDIUMAn improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360EPSS 0.2%CVE-2023-52432MEDIUMImproper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-boEPSS 0.2%CVE-2024-20842MEDIUMImproper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to EPSS 0.2%CVE-2023-42539MEDIUMPendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to acceEPSS 0.2%CVE-2023-21476HIGHOut-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrarEPSS 0.2%CVE-2023-21475HIGHOut-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrarEPSS 0.2%CVE-2025-21046LOWImproper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to rEPSS 0.2%