Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2025-20965MEDIUMImproper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.EPSS 0.1%CVE-2022-39880HIGHImproper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary EPSS 0.1%CVE-2024-34654MEDIUMImproper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My EPSS 0.1%CVE-2025-20953MEDIUMImproper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.EPSS 0.1%CVE-2025-20975MEDIUMImproper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activiEPSS 0.1%CVE-2024-20830MEDIUMIncorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.EPSS 0.1%CVE-2025-20906MEDIUMImproper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.EPSS 0.1%CVE-2025-20961MEDIUMImproper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attacEPSS 0.1%CVE-2024-20900MEDIUMImproper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authenticEPSS 0.1%CVE-2025-20989MEDIUMImproper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.EPSS 0.1%CVE-2024-20851MEDIUMImproper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch arbitrary activity wiEPSS 0.1%CVE-2025-21031MEDIUMImproper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.EPSS 0.1%CVE-2025-21019MEDIUMImproper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interactiEPSS 0.1%CVE-2025-21049MEDIUMImproper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interactEPSS 0.1%CVE-2024-20852MEDIUMImproper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to acceEPSS 0.1%CVE-2025-20942MEDIUMImproper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAIEPSS 0.1%CVE-2025-20885MEDIUMOut-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.EPSS 0.1%CVE-2026-20983HIGHImproper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitraEPSS 0.1%CVE-2024-49409MEDIUMOut-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write ouEPSS 0.1%CVE-2024-49408MEDIUMOut-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memoEPSS 0.1%