Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 20 of 24
CVE-2025-20886P4MEDIUMCVSS 4.4v12.0v13.0+1 more2025-02-04
CVE-2025-20886 [MEDIUM] CWE-922 CVE-2025-20886: Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
nvd
CVE-2025-20953P4MEDIUMCVSS 4.4v13.0v14.0+1 more2025-05-07
CVE-2025-20953 [MEDIUM] CVE-2025-20953: Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
nvd
CVE-2026-20991P4MEDIUMCVSS 4.4v14.0v15.0+1 more2026-03-16
CVE-2026-20991 [MEDIUM] CVE-2026-20991: Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privilege
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
nvd
CVE-2025-21025P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-09-03
CVE-2025-21025 [MEDIUM] CVE-2025-21025: Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attacke
Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
nvd
CVE-2025-21073P4MEDIUMCVSS 4.1v13.0v14.0+2 more2025-11-05
CVE-2025-21073 [MEDIUM] CVE-2025-21073: Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privile
Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34646P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34646 [MEDIUM] CVE-2024-34646: Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attacker
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
nvd
CVE-2023-21485P4MEDIUMCVSS 4.6v11.0v12.0+1 more2023-05-04
CVE-2023-21485 [MEDIUM] CWE-926 CVE-2023-21485: Improper export of android application components vulnerability in VideoPreviewActivity in Call Sett
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
nvd
CVE-2023-21486P4MEDIUMCVSS 4.6v11.0v12.0+1 more2023-05-04
CVE-2023-21486 [MEDIUM] CWE-926 CVE-2023-21486: Improper export of android application components vulnerability in ImagePreviewActivity in Call Sett
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
nvd
CVE-2025-20943P4MEDIUMCVSS 4.4v13.0v14.0+1 more2025-04-08
CVE-2025-20943 [MEDIUM] CWE-787 CVE-2025-20943: Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attack
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.
nvd
CVE-2024-34590P4MEDIUMCVSS 4.3v12.0v13.0+1 more2024-07-02
CVE-2024-34590 [MEDIUM] CVE-2024-34590: Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Ju
Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20958P4MEDIUMCVSS 4.4v13.0v14.0+1 more2025-05-07
CVE-2025-20958 [MEDIUM] CVE-2025-20958: Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
nvd
CVE-2025-21027P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-09-03
CVE-2025-21027 [MEDIUM] CVE-2025-21027: Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
nvd
CVE-2023-30731P4MEDIUMCVSS 4.6v12.0v13.02023-10-04
CVE-2023-30731 [MEDIUM] CVE-2023-30731: Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows phys
Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.
nvd
CVE-2023-30721P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-09-06
CVE-2023-30721 [MEDIUM] CWE-532 CVE-2023-30721: Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Rele
Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
nvd
CVE-2023-30665P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-07-06
CVE-2023-30665 [MEDIUM] CWE-125 CVE-2023-30665: Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Rele
Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.
nvd
CVE-2025-20942P4MEDIUMCVSS 4.4v13.0v14.0+1 more2025-04-08
CVE-2025-20942 [MEDIUM] CVE-2025-20942: Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Relea
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
nvd
CVE-2023-30641P4MEDIUMCVSS 4.3v13.02023-07-06
CVE-2023-30641 [MEDIUM] CVE-2023-30641: Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical at
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
nvd
CVE-2023-30711P4LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30711 [LOW] CVE-2023-30711: Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to ins
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
nvd
CVE-2023-21471P4LOWCVSS 3.3v12.0v13.02025-09-03
CVE-2023-21471 [LOW] CWE-287 CVE-2023-21471: Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attacke
Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.
nvd
CVE-2025-20907P4MEDIUMCVSS 4.4v12.0v13.0+1 more2025-02-04
CVE-2025-20907 [MEDIUM] CVE-2025-20907: Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privilege
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
nvd