Samsung Mobile Vulnerabilities and Affected Products
Vulnerabilities associated with Samsung Health.
Products
Clear product- Samsung Mobile Devices832 vulnerabilities
- Samsung Notes60 vulnerabilities
- Galaxy Store29 vulnerabilities
- Samsung Account28 vulnerabilities
- Samsung Internet27 vulnerabilities
- Smart Switch17 vulnerabilities
- Samsung Pass16 vulnerabilities
- Samsung Health15 vulnerabilities
- SmartThings15 vulnerabilities
- Samsung Members14 vulnerabilities
- Samsung Email13 vulnerabilities
- Samsung Flow8 vulnerabilities
- Blockchain Keystore7 vulnerabilities
- Samsung Blockchain Keystore7 vulnerabilities
- Samsung Pay6 vulnerabilities
- Smart Things6 vulnerabilities
- Tizen wearable devices6 vulnerabilities
- Charm by Samsung5 vulnerabilities
- Galaxy Wearable5 vulnerabilities
- Group Sharing5 vulnerabilities
- S Assistant5 vulnerabilities
- Samsung Assistant5 vulnerabilities
- Samsung Cloud5 vulnerabilities
- Samsung Gallery5 vulnerabilities
- Samsung Voice Recorder5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-21082MEDIUM | Generated title:Samsung Health Relative Path Traversal Information DisclosureRelative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. CWE-23Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21077MEDIUM | Generated title:Samsung Health Incorrect Authorization Information DisclosureIncorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. CWE-863Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21076MEDIUM | Generated title:Samsung Health Incorrect AuthorizationIncorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. CWE-863Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21056MEDIUM | Generated title:Samsung Health Improper AuthorizationImproper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information. CWE-285Jul 10, 2026 | CVSS4.8v4.0 | EPSS0.099% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21059MEDIUM | Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health. CWE-285Oct 10, 2025 | CVSS6.2v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21019MEDIUM | Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability. CWE-285Aug 6, 2025 | CVSS5.5v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34597MEDIUM | Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability. CWE-20Jul 2, 2024 | CVSS4.4v3.1 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42539MEDIUM | PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data. CWE-284Nov 7, 2023 | CVSS4.7v3.1 | EPSS0.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30737MEDIUM | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent. CWE-284Oct 4, 2023 | CVSS4.0v3.1 | EPSS0.167% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30734MEDIUM | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent. CWE-284Oct 4, 2023 | CVSS4.0v3.1 | EPSS0.167% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30723MEDIUM | Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrary file with Samsung Health privilege. CWE-20Sep 6, 2023 | CVSS5.5v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App. | CVSS2.8v3.1 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2021-25506MEDIUM | Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service. | CVSS4.0v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action. | CVSS-v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component. | CVSS-v3.1 | EPSS0.793% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |