Vulnerabilidades em Samsung Mobile

1.316 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2023-42569MEDIUMImproper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR EmEPSS 0.2%CVE-2024-34645MEDIUMImproper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.EPSS 0.2%CVE-2023-21431LOWImproper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.EPSS 0.2%CVE-2024-34660HIGHHeap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.EPSS 0.2%CVE-2025-20883MEDIUMImproper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profileEPSS 0.2%CVE-2023-42552MEDIUMImplicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12 and 14.EPSS 0.2%CVE-2022-33710Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launcEPSS 0.2%CVE-2022-33708Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch aEPSS 0.2%CVE-2022-33709Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch aEPSS 0.2%CVE-2021-25427SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device informationEPSS 0.2%CVE-2024-34674MEDIUMImproper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.EPSS 0.2%CVE-2024-49403MEDIUMImproper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the locEPSS 0.2%CVE-2024-20862MEDIUMOut-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.EPSS 0.2%CVE-2024-49407MEDIUMImproper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.EPSS 0.2%CVE-2023-21420HIGHUse of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.EPSS 0.2%CVE-2022-30709LOWImproper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.EPSS 0.2%CVE-2023-30704LOWImproper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in SecrEPSS 0.2%CVE-2022-30742LOWSensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log accesEPSS 0.2%CVE-2022-30741LOWSensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log acEPSS 0.2%CVE-2022-22283LOWImproper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.EPSS 0.2%