Samsung Android vulnerabilities

448 known vulnerabilities affecting samsung/android.

Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61

Vulnerabilities

Page 4 of 23
CVE-2025-21032MEDIUMCVSS 6.8v14.0v15.02025-09-03
CVE-2025-21032 [MEDIUM] CVE-2025-21032: Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
nvd
CVE-2025-21041MEDIUMCVSS 5.5fixed in 16.02025-09-03
CVE-2025-21041 [MEDIUM] CWE-922 CVE-2025-21041: Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attacker Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
nvd
CVE-2025-21028MEDIUMCVSS 5.5v15.0v16.02025-09-03
CVE-2025-21028 [MEDIUM] CVE-2025-21028: Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privilege Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
nvd
CVE-2025-21025MEDIUMCVSS 4.4v13.0v14.0+2 more2025-09-03
CVE-2025-21025 [MEDIUM] CVE-2025-21025: Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attacke Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
nvd
CVE-2023-21472MEDIUMCVSS 6.8v11.0v12.0+1 more2025-09-03
CVE-2023-21472 [MEDIUM] CWE-20 CVE-2023-21472: Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
nvd
CVE-2023-21477MEDIUMCVSS 5.5v11.0v12.0+1 more2025-09-03
CVE-2023-21477 [MEDIUM] CWE-125 CVE-2023-21477: Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
nvd
CVE-2023-21478MEDIUMCVSS 5.5v11.0v12.0+1 more2025-09-03
CVE-2023-21478 [MEDIUM] CVE-2023-21478: Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows lo Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
nvd
CVE-2025-21033MEDIUMCVSS 5.5v14.0v15.02025-09-03
CVE-2025-21033 [MEDIUM] CVE-2025-21033: Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2025-21029LOWCVSS 3.3v13.0v14.0+2 more2025-09-03
CVE-2025-21029 [LOW] CVE-2025-21029: Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows loc Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
nvd
CVE-2025-21026LOWCVSS 3.3v13.0v14.0+2 more2025-09-03
CVE-2025-21026 [LOW] CVE-2025-21026: Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows lo Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
nvd
CVE-2023-21471LOWCVSS 3.3v12.0v13.02025-09-03
CVE-2023-21471 [LOW] CWE-287 CVE-2023-21471: Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attacke Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.
nvd
CVE-2023-21469LOWCVSS 3.3v11.0v12.0+1 more2025-09-03
CVE-2023-21469 [LOW] CVE-2023-21469: Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local atta Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
nvd
CVE-2023-21470LOWCVSS 3.3v11.0v12.0+1 more2025-09-03
CVE-2023-21470 [LOW] CVE-2023-21470: Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local atta Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.
nvd
CVE-2023-21466LOWCVSS 3.3v11.0v12.0+1 more2025-09-03
CVE-2023-21466 [LOW] CWE-287 CVE-2023-21466: PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Releas PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
nvd
CVE-2025-21015HIGHCVSS 7.1v15.02025-08-06
CVE-2025-21015 [HIGH] CWE-22 CVE-2025-21015: Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
nvd
CVE-2025-21010MEDIUMCVSS 6.0v13.0v14.0+2 more2025-08-06
CVE-2025-21010 [MEDIUM] CVE-2025-21010: Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privile Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
nvd
CVE-2025-21014MEDIUMCVSS 5.5v13.0v14.0+1 more2025-08-06
CVE-2025-21014 [MEDIUM] CVE-2025-21014: Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 al Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2025-20990LOWCVSS 3.3v13.0v14.0+1 more2025-08-06
CVE-2025-20990 [LOW] CVE-2025-20990: Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
nvd
CVE-2025-21006HIGHCVSS 7.8fixed in 15.02025-07-08
CVE-2025-21006 [HIGH] CWE-787 CVE-2025-21006: Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-21008MEDIUMCVSS 5.5fixed in 15.02025-07-08
CVE-2025-21008 [MEDIUM] CWE-125 CVE-2025-21008: Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attacke Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
nvd