Samsung Mobile Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Samsung Mobile products.
Products
- Samsung Mobile Devices832 vulnerabilities
- Samsung Notes60 vulnerabilities
- Galaxy Store29 vulnerabilities
- Samsung Account28 vulnerabilities
- Samsung Internet27 vulnerabilities
- Smart Switch17 vulnerabilities
- Samsung Pass16 vulnerabilities
- Samsung Health15 vulnerabilities
- SmartThings15 vulnerabilities
- Samsung Members14 vulnerabilities
- Samsung Email13 vulnerabilities
- Samsung Flow8 vulnerabilities
- Blockchain Keystore7 vulnerabilities
- Samsung Blockchain Keystore7 vulnerabilities
- Samsung Pay6 vulnerabilities
- Smart Things6 vulnerabilities
- Tizen wearable devices6 vulnerabilities
- Charm by Samsung5 vulnerabilities
- Galaxy Wearable5 vulnerabilities
- Group Sharing5 vulnerabilities
- S Assistant5 vulnerabilities
- Samsung Assistant5 vulnerabilities
- Samsung Cloud5 vulnerabilities
- Samsung Gallery5 vulnerabilities
- Samsung Voice Recorder5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-21084MEDIUM | Generated title:Samsung SmartThings Improper Access Control Information DisclosureImproper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. CWE-284Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.091% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21083MEDIUM | Generated title:Samsung Smart Switch Improper Input Validation Leading to Sensitive Data AccessImproper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. CWE-20Aug 10, 2026 | CVSS6.8v4.0 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21082MEDIUM | Generated title:Samsung Health Relative Path Traversal Information DisclosureRelative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. CWE-23Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21081MEDIUM | Generated title:SamsungPassAutofill Improper Export of Android Application ComponentsImproper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. CWE-926Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.091% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21080MEDIUM | Generated title:Samsung Smart Switch Cleartext Storage of Sensitive InformationCleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. CWE-312Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21079HIGH | Generated title:Samsung Smart Switch Missing Encryption for Sensitive DataMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. CWE-311Aug 10, 2026 | CVSS7.0v4.0 | EPSS0.065% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21078MEDIUM | Generated title:Samsung Smart Switch Insufficient Verification of Data AuthenticityInsufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. CWE-345Aug 10, 2026 | CVSS4.7v4.0 | EPSS0.097% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21077MEDIUM | Generated title:Samsung Health Incorrect Authorization Information DisclosureIncorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. CWE-863Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21076MEDIUM | Generated title:Samsung Health Incorrect AuthorizationIncorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. CWE-863Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21075MEDIUM | Generated title:Samsung My Galaxy Custom URL Scheme Improper AuthorizationImproper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. CWE-939Aug 10, 2026 | CVSS5.3v4.0 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21074HIGH | Generated title:Samsung Bixby Incorrect Default Permissions Local Privilege EscalationIncorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege. CWE-276Aug 10, 2026 | CVSS7.2v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21073MEDIUM | Generated title:Samsung Galaxy Themes Improper Input Validation VulnerabilityImproper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. CWE-20Aug 10, 2026 | CVSS5.2v4.0 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21072MEDIUM | Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds WriteImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21071MEDIUM | Generated title:Samsung Mobile Devices libsavsvc.so MPEG4 Codec Out-of-Bounds WriteImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21070MEDIUM | Generated title:Samsung Mobile Devices Improper Input Validation in Samsung MessageImproper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.145% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21069MEDIUM | Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds WriteIncorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-681Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21068HIGH | Generated title:Samsung Mobile Devices libril_sem.so Stack-based Buffer OverflowStack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. CWE-121Aug 10, 2026 | CVSS8.4v4.0 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21067MEDIUM | Generated title:Samsung Mobile Devices libsmsd.so Out-of-Bounds WriteImproper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21066MEDIUM | Generated title:Samsung libcodec2_sec_flacdec.so Improper Input Validation Leading to Out-of-Bounds WriteImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21065MEDIUM | Generated title:Samsung Mobile libcodec2secqcelpdec Out-of-Bounds WriteOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS4.4v4.0 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21064HIGH | Generated title:Samsung Mobile Devices Weaver Improper Access ControlImproper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. CWE-284Aug 10, 2026 | CVSS7.0v4.0 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21063MEDIUM | Generated title:Samsung Mobile Devices AppLock Improper Export of Android Application ComponentsImproper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. CWE-926Aug 10, 2026 | CVSS6.8v4.0 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21062MEDIUM | Generated title:Samsung Mobile Devices SemClipboardService Authorization BypassAuthorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. CWE-939Aug 10, 2026 | CVSS4.8v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21061MEDIUM | Generated title:Samsung Dialer Improper Input ValidationImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. CWE-20Aug 10, 2026 | CVSS6.0v4.0 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21060MEDIUM | Generated title:Samsung Contacts Improper Input Validation Leading to Cross-Profile Data AccessImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. CWE-20Aug 10, 2026 | CVSS6.7v4.0 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |