Vulnerabilities in Samsung Mobile

1,391 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2026-21053MEDIUMImproper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the applicationEPSS 0.2%CVE-2021-25430—Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the BEPSS 0.2%CVE-2021-25429—Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to accessEPSS 0.2%CVE-2026-21078MEDIUMInsufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to EPSS 0.2%CVE-2024-20893MEDIUMImproper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruptionEPSS 0.2%CVE-2025-21046LOWImproper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to rEPSS 0.2%CVE-2023-30643HIGHMissing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary nonEPSS 0.2%CVE-2021-25390MEDIUMIntent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.EPSS 0.2%CVE-2025-20905MEDIUMOut-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-ofEPSS 0.2%CVE-2023-21426MEDIUMHardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.EPSS 0.2%CVE-2023-30717MEDIUMSensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.EPSS 0.2%CVE-2025-20904MEDIUMOut-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.EPSS 0.2%CVE-2023-30715MEDIUMImproper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in WeatEPSS 0.2%CVE-2024-20836LOWOut of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out oEPSS 0.2%CVE-2025-20913MEDIUMOut-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds EPSS 0.2%CVE-2022-39861MEDIUMUnprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privileEPSS 0.2%CVE-2024-49404MEDIUMImproper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android EPSS 0.2%CVE-2023-21462MEDIUMThe sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 EPSS 0.2%CVE-2023-21421MEDIUMImproper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allowsEPSS 0.2%CVE-2025-21030MEDIUMImproper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows locaEPSS 0.2%