Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 11 of 24
CVE-2024-20879P4HIGHCVSS 7.1v12.0v13.0+1 more2024-06-04
CVE-2024-20879 [HIGH] CVE-2024-20879: Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows loca
Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-20988P4HIGHCVSS 7.1v13.0v14.0+1 more2025-06-04
CVE-2025-20988 [HIGH] CWE-125 CVE-2025-20988: Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged a
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
nvd
CVE-2023-42533P4MEDIUMCVSS 6.8v12.0v13.02023-11-07
CVE-2023-42533 [MEDIUM] CVE-2023-42533: Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physica
Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
nvd
CVE-2026-21009P4MEDIUMCVSS 6.8v14.0v15.0+1 more2026-04-13
CVE-2026-21009 [MEDIUM] CWE-754 CVE-2026-21009: Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
nvd
CVE-2026-21021P4MEDIUMCVSS 6.8v16.02026-05-13
CVE-2026-21021 [MEDIUM] CVE-2026-21021: Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to l
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
nvd
CVE-2024-20832P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-03-05
CVE-2024-20832 [MEDIUM] CWE-787 CVE-2024-20832: Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged
Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2025-20905P4MEDIUMCVSS 6.7v12.0v13.0+1 more2025-02-04
CVE-2025-20905 [MEDIUM] CWE-125 CVE-2025-20905: Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privi
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
nvd
CVE-2025-20983P4MEDIUMCVSS 6.7v14.0v15.02025-07-08
CVE-2025-20983 [MEDIUM] CWE-787 CVE-2025-20983: Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 al
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-20982P4MEDIUMCVSS 6.7v14.0v15.02025-07-08
CVE-2025-20982 [MEDIUM] CWE-787 CVE-2025-20982: Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 all
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2024-20815P4MEDIUMCVSS 6.5v11.0v12.0+2 more2024-02-06
CVE-2024-20815 [MEDIUM] CWE-287 CVE-2024-20815: Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Fe
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
nvd
CVE-2024-20816P4MEDIUMCVSS 6.5v11.0v12.0+2 more2024-02-06
CVE-2024-20816 [MEDIUM] CWE-287 CVE-2024-20816: Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR F
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
nvd
CVE-2026-21008P4MEDIUMCVSS 6.5v14.0v15.0+1 more2026-04-13
CVE-2026-21008 [MEDIUM] CVE-2026-21008: Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacke
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
nvd
CVE-2023-21479P4MEDIUMCVSS 5.3v13.02025-09-03
CVE-2023-21479 [MEDIUM] CVE-2023-21479: Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01
Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
nvd
CVE-2025-20944P4HIGHCVSS 7.1v13.0v14.0+1 more2025-04-08
CVE-2025-20944 [HIGH] CWE-125 CVE-2025-20944: Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows loca
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.
nvd
CVE-2023-21490P4HIGHCVSS 7.1v11.0v12.0+1 more2023-05-04
CVE-2023-21490 [HIGH] CWE-284 CVE-2023-21490: Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker t
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
nvd
CVE-2025-21032P4MEDIUMCVSS 6.8v14.0v15.02025-09-03
CVE-2025-21032 [MEDIUM] CVE-2025-21032: Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
nvd
CVE-2025-20993P4MEDIUMCVSS 6.8v13.0v14.0+1 more2025-06-04
CVE-2025-20993 [MEDIUM] CWE-787 CVE-2025-20993: Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2024-20861P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-07
CVE-2024-20861 [MEDIUM] CWE-416 CVE-2024-20861: Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged a
Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.
nvd
CVE-2024-20842P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-04-02
CVE-2024-20842 [MEDIUM] CWE-787 CVE-2024-20842: Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release
Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-20904P4MEDIUMCVSS 6.7v12.0v13.0+1 more2025-02-04
CVE-2025-20904 [MEDIUM] CWE-787 CVE-2025-20904: Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged att
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
nvd