Samsung Mobile Vulnerabilities and Affected Products
Vulnerabilities associated with Samsung Mobile Devices.
Products
Clear product- Samsung Mobile Devices832 vulnerabilities
- Samsung Notes60 vulnerabilities
- Galaxy Store29 vulnerabilities
- Samsung Account28 vulnerabilities
- Samsung Internet27 vulnerabilities
- Smart Switch17 vulnerabilities
- Samsung Pass16 vulnerabilities
- Samsung Health15 vulnerabilities
- SmartThings15 vulnerabilities
- Samsung Members14 vulnerabilities
- Samsung Email13 vulnerabilities
- Samsung Flow8 vulnerabilities
- Blockchain Keystore7 vulnerabilities
- Samsung Blockchain Keystore7 vulnerabilities
- Samsung Pay6 vulnerabilities
- Smart Things6 vulnerabilities
- Tizen wearable devices6 vulnerabilities
- Charm by Samsung5 vulnerabilities
- Galaxy Wearable5 vulnerabilities
- Group Sharing5 vulnerabilities
- S Assistant5 vulnerabilities
- Samsung Assistant5 vulnerabilities
- Samsung Cloud5 vulnerabilities
- Samsung Gallery5 vulnerabilities
- Samsung Voice Recorder5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-21073MEDIUM | Generated title:Samsung Galaxy Themes Improper Input Validation VulnerabilityImproper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. CWE-20Aug 10, 2026 | CVSS5.2v4.0 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21072MEDIUM | Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds WriteImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21071MEDIUM | Generated title:Samsung Mobile Devices libsavsvc.so MPEG4 Codec Out-of-Bounds WriteImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21070MEDIUM | Generated title:Samsung Mobile Devices Improper Input Validation in Samsung MessageImproper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.145% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21069MEDIUM | Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds WriteIncorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-681Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21068HIGH | Generated title:Samsung Mobile Devices libril_sem.so Stack-based Buffer OverflowStack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. CWE-121Aug 10, 2026 | CVSS8.4v4.0 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21067MEDIUM | Generated title:Samsung Mobile Devices libsmsd.so Out-of-Bounds WriteImproper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21066MEDIUM | Generated title:Samsung libcodec2_sec_flacdec.so Improper Input Validation Leading to Out-of-Bounds WriteImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21065MEDIUM | Generated title:Samsung Mobile libcodec2secqcelpdec Out-of-Bounds WriteOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS4.4v4.0 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21064HIGH | Generated title:Samsung Mobile Devices Weaver Improper Access ControlImproper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. CWE-284Aug 10, 2026 | CVSS7.0v4.0 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21063MEDIUM | Generated title:Samsung Mobile Devices AppLock Improper Export of Android Application ComponentsImproper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. CWE-926Aug 10, 2026 | CVSS6.8v4.0 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21062MEDIUM | Generated title:Samsung Mobile Devices SemClipboardService Authorization BypassAuthorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. CWE-939Aug 10, 2026 | CVSS4.8v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21061MEDIUM | Generated title:Samsung Dialer Improper Input ValidationImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. CWE-20Aug 10, 2026 | CVSS6.0v4.0 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21060MEDIUM | Generated title:Samsung Contacts Improper Input Validation Leading to Cross-Profile Data AccessImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. CWE-20Aug 10, 2026 | CVSS6.7v4.0 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21059MEDIUM | Generated title:Samsung Contacts Improper Export of Android Application ComponentsImproper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. CWE-926Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21058MEDIUM | Generated title:Samsung Contacts Improper Input Validation Local Arbitrary File DeletionImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. CWE-20Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21047HIGH | Generated title:Samsung ImsService Out-of-Bounds Write Remote Code ExecutionOut-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. CWE-787Jul 28, 2026 | CVSS8.3v4.0 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21052MEDIUM | Generated title:Samsung SemClipboardService Path Traversal VulnerabilityPath traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. CWE-22Jul 10, 2026 | CVSS6.8v4.0 | EPSS0.131% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21051MEDIUM | Generated title:Samsung Mobile Devices WLAN Security Incorrect Default PermissionsIncorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings. CWE-276Jul 10, 2026 | CVSS5.1v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21050MEDIUM | Generated title:Samsung SmartThingsKit Improper Access Control Information DisclosureImproper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. CWE-284Jul 10, 2026 | CVSS5.1v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21049HIGH | Generated title:Samsung libpadm.so Out-of-Bounds Write Local Privilege EscalationOut-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code. CWE-787Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21048HIGH | Generated title:Samsung libimagecodec.media.quram.so DNG Parsing Out-of-Bounds WriteOut-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. CWE-787Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.387% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21046HIGH | Generated title:Samsung fabricKeymaster Trustlet TOCTOU Race ConditionTime-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code. CWE-367Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.096% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21045HIGH | Generated title:Samsung libimagecodec.media.quram.so TIFF Parsing Out-of-Bounds WriteOut-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. CWE-787Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.465% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21044MEDIUM | Generated title:Samsung KnoxGuardManager Improper AuthorizationImproper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. CWE-269Jul 10, 2026 | CVSS5.8v4.0 | EPSS0.096% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |