Vulnerabilities in Samsung Mobile

1,391 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2026-21033MEDIUMImproper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attEPSS 0.1%CVE-2026-21025MEDIUMIncorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.EPSS 0.1%CVE-2026-21013MEDIUMIncorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.EPSS 0.1%CVE-2026-21112MEDIUMImproper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilegEPSS 0.1%CVE-2021-25519MEDIUMAn improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without pEPSS 0.1%CVE-2026-21029MEDIUMImproper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to executeEPSS 0.1%CVE-2026-21012MEDIUMExternal control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privEPSS 0.1%CVE-2026-21105MEDIUMImproper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access seEPSS 0.1%CVE-2026-20993MEDIUMImproper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved inforEPSS 0.1%CVE-2026-21015MEDIUMIncorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.EPSS 0.1%CVE-2022-33728MEDIUMExposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via EPSS 0.1%CVE-2022-33722MEDIUMImplicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC addressEPSS 0.1%CVE-2026-21024MEDIUMImproper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigger privileged functiEPSS 0.1%CVE-2022-33714MEDIUMImproper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting valueEPSS 0.1%CVE-2022-33726LOWUnprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.EPSS 0.1%CVE-2022-33702MEDIUMImproper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass KnoxgEPSS 0.1%CVE-2022-33731MEDIUMImproper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary coEPSS 0.1%CVE-2022-36856MEDIUMImproper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via unEPSS 0.1%CVE-2022-36861MEDIUMCustom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystEPSS 0.1%CVE-2022-33718MEDIUMAn improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the liEPSS 0.1%