Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 19 of 24
CVE-2025-21009P4MEDIUMCVSS 5.5fixed in 15.02025-07-08
CVE-2025-21009 [MEDIUM] CWE-125 CVE-2025-21009: Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows loc
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
nvd
CVE-2025-20991P4MEDIUMCVSS 5.1v13.0v14.0+1 more2025-06-04
CVE-2025-20991 [MEDIUM] CVE-2025-20991: Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allow
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
nvd
CVE-2024-34639P4MEDIUMCVSS 4.6v12.0v13.0+1 more2024-09-04
CVE-2024-34639 [MEDIUM] CWE-755 CVE-2024-34639: Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows ph
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
nvd
CVE-2024-20882P4MEDIUMCVSS 4.6v12.0v13.0+1 more2024-06-04
CVE-2024-20882 [MEDIUM] CWE-125 CVE-2024-20882: Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical atta
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
nvd
CVE-2024-49402P4MEDIUMCVSS 4.6v14.02024-11-06
CVE-2024-49402 [MEDIUM] CVE-2024-49402: Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to a
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
nvd
CVE-2023-42568P4MEDIUMCVSS 4.4≥ 12.0, < 13.0v13.02023-12-05
CVE-2023-42568 [MEDIUM] CVE-2023-42568: Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
nvd
CVE-2023-21460P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-03-16
CVE-2023-21460 [MEDIUM] CWE-287 CVE-2023-21460: Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
nvd
CVE-2025-58475P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-12-02
CVE-2025-58475 [MEDIUM] CVE-2025-58475: Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged a
Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-21072P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-12-02
CVE-2025-21072 [MEDIUM] CWE-787 CVE-2025-21072: Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 all
Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-20883P4MEDIUMCVSS 4.6v12.0v13.0+1 more2025-02-04
CVE-2025-20883 [MEDIUM] CVE-2025-20883: Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
nvd
CVE-2024-34645P4MEDIUMCVSS 4.6v12.0v13.02024-09-04
CVE-2024-34645 [MEDIUM] CVE-2024-34645: Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers t
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
nvd
CVE-2024-34674P4MEDIUMCVSS 4.6v12.0v13.0+1 more2024-11-06
CVE-2024-34674 [MEDIUM] CVE-2024-34674: Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to acc
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
nvd
CVE-2024-34675P4MEDIUMCVSS 4.6v14.02024-11-06
CVE-2024-34675 [MEDIUM] CVE-2024-34675: Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to tem
Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.
nvd
CVE-2024-20894P4MEDIUMCVSS 4.3v12.0v13.0+1 more2024-07-02
CVE-2024-20894 [MEDIUM] CWE-755 CVE-2024-20894: Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34642P4MEDIUMCVSS 4.6v12.0v13.0+1 more2024-09-04
CVE-2024-34642 [MEDIUM] CWE-863 CVE-2024-34642: Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to t
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
nvd
CVE-2025-20884P4MEDIUMCVSS 4.6v12.0v13.0+1 more2025-02-04
CVE-2025-20884 [MEDIUM] CVE-2025-20884: Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
nvd
CVE-2023-30714P4MEDIUMCVSS 4.6v11.0v12.0+1 more2023-09-06
CVE-2023-30714 [MEDIUM] CVE-2023-30714: Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
nvd
CVE-2025-58476P4MEDIUMCVSS 4.6v13.0v14.0+2 more2025-12-02
CVE-2025-58476 [MEDIUM] CWE-125 CVE-2025-58476: Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attac
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
nvd
CVE-2024-34592P4MEDIUMCVSS 4.3v12.0v13.0+1 more2024-07-02
CVE-2024-34592 [MEDIUM] CVE-2024-34592: Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 a
Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34591P4MEDIUMCVSS 4.3v12.0v13.0+1 more2024-07-02
CVE-2024-34591 [MEDIUM] CVE-2024-34591: Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Ju
Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
nvd