Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 16 of 24
CVE-2024-34606P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34606 [MEDIUM] CVE-2024-34606: Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2024-34605P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34605 [MEDIUM] CVE-2024-34605: Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attacke
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2024-34608P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34608 [MEDIUM] CVE-2024-34608: Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attack
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2024-34604P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34604 [MEDIUM] CVE-2024-34604: Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2024-34607P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34607 [MEDIUM] CVE-2024-34607: Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attacker
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2023-30698P4MEDIUMCVSS 5.5v13.02023-08-10
CVE-2023-30698 [MEDIUM] CVE-2023-30698: Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local at
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
nvd
CVE-2025-20909P4MEDIUMCVSS 5.5v14.02025-03-06
CVE-2025-20909 [MEDIUM] CVE-2025-20909: Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allow
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2024-34680P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-11-06
CVE-2024-34680 [MEDIUM] CVE-2024-34680: Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allow
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2024-34648P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34648 [MEDIUM] CWE-276 CVE-2024-34648: Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allo
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
nvd
CVE-2024-34603P4MEDIUMCVSS 5.5v13.0v14.02024-07-08
CVE-2024-34603 [MEDIUM] CVE-2024-34603: Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.
nvd
CVE-2024-20898P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-20898 [MEDIUM] CVE-2024-20898: Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Ju
Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2024-34616P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34616 [MEDIUM] CWE-276 CVE-2024-34616: Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 al
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.
nvd
CVE-2025-20955P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20955 [MEDIUM] CVE-2025-20955: Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR M
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
nvd
CVE-2025-21014P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-08-06
CVE-2025-21014 [MEDIUM] CVE-2025-21014: Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 al
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2024-34611P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34611 [MEDIUM] CVE-2024-34611: Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get
Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2025-21003P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-07-08
CVE-2025-21003 [MEDIUM] CWE-922 CVE-2025-21003: Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows lo
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2025-21041P4MEDIUMCVSS 5.5fixed in 16.02025-09-03
CVE-2025-21041 [MEDIUM] CWE-922 CVE-2025-21041: Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attacker
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
nvd
CVE-2025-21001P4MEDIUMCVSS 5.5v14.0v15.02025-07-08
CVE-2025-21001 [MEDIUM] CVE-2025-21001: Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
nvd
CVE-2025-20959P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20959 [MEDIUM] CVE-2025-20959: Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Releas
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2025-21002P4MEDIUMCVSS 5.5v14.0v15.02025-07-08
CVE-2025-21002 [MEDIUM] CVE-2025-21002: Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
nvd