Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2024-20882MEDIUMOut-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.EPSS 0.2%CVE-2022-30716MEDIUMUnprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access tEPSS 0.2%CVE-2024-49402MEDIUMImproper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profilesEPSS 0.2%CVE-2022-28791MEDIUMImproper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored EPSS 0.2%CVE-2021-25527LOWImproper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to accesEPSS 0.2%CVE-2023-42537HIGHAn improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read EPSS 0.2%CVE-2022-28793MEDIUMGiven the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT EPSS 0.2%CVE-2022-24923MEDIUMImproper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to loEPSS 0.2%CVE-2023-42536HIGHAn improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read andEPSS 0.2%CVE-2021-25522MEDIUMInsecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captuEPSS 0.2%CVE-2022-30748MEDIUMUnprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.EPSS 0.2%CVE-2023-21456CRITICALPath traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uEPSS 0.2%CVE-2022-39893LOWSensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers EPSS 0.2%CVE-2021-25399—Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.EPSS 0.2%CVE-2021-25499HIGHIntent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access contEPSS 0.2%CVE-2023-42568HIGHImproper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files witEPSS 0.2%CVE-2025-20898MEDIUMImproper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profilEPSS 0.2%CVE-2021-25465LOWAn improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.EPSS 0.2%CVE-2022-30740MEDIUMImproper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.EPSS 0.2%CVE-2021-25463MEDIUMImproper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.EPSS 0.2%