Samsung Flow vulnerabilities

6 known vulnerabilities affecting samsung/flow.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-20972MEDIUMCVSS 5.5fixed in 4.9.17.62025-05-07
CVE-2025-20972 [MEDIUM] CVE-2025-20972: Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allo Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.
nvd
CVE-2025-20971MEDIUMCVSS 5.5fixed in 4.9.17.62025-05-07
CVE-2025-20971 [MEDIUM] CVE-2025-20971: Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.
nvd
CVE-2024-49407MEDIUMCVSS 4.6fixed in 4.9.15.72024-11-06
CVE-2024-49407 [MEDIUM] CVE-2024-49407: Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to acces Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.
nvd
CVE-2024-34600LOWCVSS 3.3fixed in 4.9.13.02024-07-02
CVE-2024-34600 [MEDIUM] CVE-2024-34600: Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.
nvd
CVE-2023-21444HIGHCVSS 8.8fixed in 4.9.14.02023-02-09
CVE-2023-21444 [HIGH] CWE-326 CVE-2023-21444: Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to d Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.
nvd
CVE-2023-21443HIGHCVSS 8.8fixed in 4.9.042023-02-09
CVE-2023-21443 [HIGH] CWE-326 CVE-2023-21443: Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adj Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.
nvd