Samsung
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Samsung product.
RSS Feeds for Samsung security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Samsung products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Samsung Sorted by Most Security Vulnerabilities since 2018
Recent Samsung Security Advisories
| Advisory | Title | Published |
|---|---|---|
| SMR-Sep-2026 | Samsung Mobile Security Maintenance Release SMR-Sep-2026 | September 8, 2026 |
| SMR-Aug-2026 | Samsung Mobile Security Maintenance Release SMR-Aug-2026 | August 4, 2026 |
| SMR-Jul-2026 | Samsung Mobile Security Maintenance Release SMR-Jul-2026 | July 7, 2026 |
| SMR-Jun-2026 | Samsung Mobile Security Maintenance Release SMR-Jun-2026 | June 2, 2026 |
| SMR-May-2026 | Samsung Mobile Security Maintenance Release SMR-May-2026 | May 6, 2026 |
| SMR-Apr-2026 | Samsung Mobile Security Maintenance Release SMR-Apr-2026 | April 7, 2026 |
| SMR-Mar-2026 | Samsung Mobile Security Maintenance Release SMR-Mar-2026 | March 3, 2026 |
| SMR-Feb-2026 | Samsung Mobile Security Maintenance Release SMR-Feb-2026 | February 3, 2026 |
| SMR-Jan-2026 | Samsung Mobile Security Maintenance Release SMR-Jan-2026 | January 6, 2026 |
| SMR-Dec-2025 | Samsung Mobile Security Maintenance Release SMR-Dec-2025 | December 2, 2025 |
Known Exploited Samsung Vulnerabilities
The following Samsung vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Samsung MagicINFO 9 Server Path Traversal Vulnerability |
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. CVE-2024-7399 Exploit Probability: 91.9% |
April 24, 2026 |
| Samsung Mobile Devices Out-of-Bounds Write Vulnerability |
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. CVE-2025-21042 Exploit Probability: 33.1% |
November 10, 2025 |
| Samsung Mobile Devices Out-of-Bounds Write Vulnerability |
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. CVE-2025-21043 Exploit Probability: 1.9% |
October 2, 2025 |
| Samsung MagicINFO 9 Server Path Traversal Vulnerability |
Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. CVE-2025-4632 Exploit Probability: 24.4% |
May 22, 2025 |
| Samsung Mobile Devices Use-After-Free Vulnerability |
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. CVE-2022-22265 Exploit Probability: 0.4% |
September 18, 2023 |
| Samsung Mobile Devices Out-of-Bounds Read Vulnerability |
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. CVE-2021-25487 Exploit Probability: 0.6% |
June 29, 2023 |
| Samsung Mobile Devices Improper Input Validation Vulnerability |
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. CVE-2021-25489 Exploit Probability: 0.5% |
June 29, 2023 |
| Samsung Mobile Devices Race Condition Vulnerability |
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. CVE-2021-25394 Exploit Probability: 0.4% |
June 29, 2023 |
| Samsung Mobile Devices Race Condition Vulnerability |
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. CVE-2021-25395 Exploit Probability: 0.4% |
June 29, 2023 |
| Samsung Mobile Devices Unspecified Vulnerability |
Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. CVE-2021-25371 Exploit Probability: 0.8% |
June 29, 2023 |
| Samsung Mobile Devices Improper Boundary Check Vulnerability |
Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. CVE-2021-25372 Exploit Probability: 0.8% |
June 29, 2023 |
| Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability |
Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass. CVE-2023-21492 Exploit Probability: 2.6% |
May 19, 2023 |
| Samsung Mobile Devices Improper Access Control Vulnerability |
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. CVE-2021-25337 Exploit Probability: 2.8% |
November 8, 2022 |
| Samsung Mobile Devices Improper Access Control Vulnerability |
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. CVE-2021-25369 Exploit Probability: 1.1% |
November 8, 2022 |
| Samsung Mobile Devices Memory Corruption Vulnerability |
Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. CVE-2021-25370 Exploit Probability: 0.9% |
November 8, 2022 |
The vulnerability CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Samsung vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 161 vulnerabilities in Samsung with an average score of 6.5 out of ten. Last year, in 2025 Samsung had 191 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Samsung in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.24.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 161 | 6.53 |
| 2025 | 191 | 6.29 |
| 2024 | 230 | 5.95 |
| 2023 | 236 | 6.33 |
| 2022 | 147 | 5.66 |
| 2021 | 73 | 5.73 |
| 2020 | 10 | 8.10 |
| 2019 | 7 | 7.00 |
| 2018 | 20 | 7.71 |
It may take a day or so for new Samsung vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Samsung Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-21113 | Sep 09, 2026 |
Samsung Visual Voicemail <20.1.00.05: Improper Export (Local Call)Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. |
|
| CVE-2026-21112 | Sep 09, 2026 |
Samsung Tips Improper Input Validation Allows Local Activity Launch (Android 17)Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability. |
|
| CVE-2026-21111 | Sep 09, 2026 |
SA-2026-21111 OOB write in libsthmbc.so before One UI 8.5Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21110 | Sep 09, 2026 |
OOB write in libsavscmn.so before OneUI 8.5 enables local code execOut-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code. |
|
| CVE-2026-21109 | Sep 09, 2026 |
Android Watch 17 Watch Plugin Improper Access ControlImproper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information. |
|
| CVE-2026-21108 | Sep 09, 2026 |
Android Bixby Touch Improper Component Export (pre4.3.01.17)Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information. |
|
| CVE-2026-21107 | Sep 09, 2026 |
Samsung Notes OOB Write v<4.4.45.5 (Local)Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21106 | Sep 09, 2026 |
Samsung Cloud Assistant <9.0.5 Intent Mis-Verification Allows Local DisableImproper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings. |
|
| CVE-2026-21105 | Sep 09, 2026 |
Android Collection Improper Access Control <1.0.1.14 (15) / 2.0.02.7 (16)Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information. |
|
| CVE-2026-21104 | Sep 09, 2026 |
Heap Buffer Overflow in Samsung KnoxVault Trustlet (CVE-2026-21104)Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code. |
|
| CVE-2026-21103 | Sep 09, 2026 |
GalaxyDiagnostics Path Traversal Allows Physical Attackers to Read System FilesPath traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege. |
|
| CVE-2026-21102 | Sep 09, 2026 |
DualDAR UAF Allows Root Code Exec on Samsung MobileUse after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege. |
|
| CVE-2026-21101 | Sep 09, 2026 |
DualDAR driver input validation flaw allows local privilege escalationImproper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege. |
|
| CVE-2026-21100 | Sep 09, 2026 |
Samsung SystemUI Improper Access Control: Local Attacker Arbitrary ActivityImproper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity. |
|
| CVE-2026-21099 | Sep 09, 2026 |
Samsung SettingsProvider Improper Access Control (CVE-2026-21099)Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information. |
|
| CVE-2026-21098 | Sep 09, 2026 |
CVE-2026-21098: Improper Access Control in Samsung Link to WindowsImproper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction. |
|
| CVE-2026-21097 | Sep 09, 2026 |
Android Local Privilege Escalation via ActivityTaskManagerServiceImproper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity. |
|
| CVE-2026-21096 | Sep 09, 2026 |
Heap Overflow in Samsung libimagecodec JPEG Decoder Enables RCEHeap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. |
|
| CVE-2026-21095 | Sep 09, 2026 |
Heap Buffer Overflow in libimagecodec.quram.so DNG Decoder (Samsung Android)Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. |
|
| CVE-2026-21094 | Sep 09, 2026 |
wpa_supplicant OOB Write via Improper Input ValidationImproper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory. |
|
| CVE-2026-21093 | Sep 09, 2026 |
PROCA trustlet: Stack buffer overflow allows local privilege escalation on Samsung MobileStack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. |
|
| CVE-2026-21092 | Sep 09, 2026 |
Android ImsService Path Traversal Enables System-Privileged Image CreationPath traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege. |
|
| CVE-2026-21091 | Sep 09, 2026 |
Samsung Mobile libcodec2secevrcdec.so OOB Write (CVE-2026-21091)Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21090 | Sep 09, 2026 |
Samsung libsaviextractor.so OOB write allows local memory corruptionOut-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21089 | Sep 09, 2026 |
Samsung Mobile libsubextractor SO OOB Write via Input Validation FlawImproper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21088 | Sep 09, 2026 |
Improper Input Validation in libsubextractor.so OOB WriteImproper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21087 | Sep 09, 2026 |
Samsung Android libmdnie.so OOB Write Enables System Privilege EscalationOut-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege. |
|
| CVE-2026-21086 | Sep 09, 2026 |
Samsung Mobile ProxyHandler Local Access Unauthorized Access CVE-2026-21086Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. |
|
| CVE-2026-21085 | Sep 09, 2026 |
Keymaster Trustlet OOB Write (CVE-2026-21085) Samsung AndroidOut-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. |
|
| CVE-2026-19588 | Aug 12, 2026 |
Samsung rlottie IntegerOverflowBufferOverflowInteger Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. |
|
| CVE-2026-19587 | Aug 12, 2026 |
Samsung rlottie Uncontrolled Resource Consumption: Excessive AllocationUncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. |
|
| CVE-2026-21084 | Aug 10, 2026 |
SmartThings <1.8.47.24 Improper Access Local Attacker Sensitive InfoImproper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. |
|
| CVE-2026-21083 | Aug 10, 2026 |
Smart Switch <3.7.72.6 Improper Input Validation Allows Adjacent AccessImproper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. |
|
| CVE-2026-21082 | Aug 10, 2026 |
Samsung Health <7.0.0 RPT: Relative Path Traversal Local Privileged AccessRelative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
|
| CVE-2026-21081 | Aug 10, 2026 |
SamsungPassAutofill Improper Export of Components before 5.2.10.xImproper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. |
|
| CVE-2026-21080 | Aug 10, 2026 |
Smart Switch Cleartext Storage before v3.7.72.6 (Adjacent Access)Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. |
|
| CVE-2026-21079 | Aug 10, 2026 |
Missing encryption in Samsung Smart Switch <3.7.72.6 allows data interceptionMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. |
|
| CVE-2026-21078 | Aug 10, 2026 |
Smart Switch < 3.7.72.6: Auth Bypass in Trouble Scan ModeInsufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. |
|
| CVE-2026-21077 | Aug 10, 2026 |
Samsung Health <7.0.0 Improper Authorization Local Access to Sensitive DataIncorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
|
| CVE-2026-21076 | Aug 10, 2026 |
Samsung Health Before 7.0.0 Local Auth Flaw Exposes Sensitive DataIncorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
|
| CVE-2026-21075 | Aug 10, 2026 |
Improper Auth in My Galaxy <6.3: Custom URL Scheme accessImproper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. |
|
| CVE-2026-21074 | Aug 10, 2026 |
Bixby Local Privileges Escalation via Default Permissions (<=4.0.86.0)Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege. |
|
| CVE-2026-21073 | Aug 10, 2026 |
Samsung Galaxy Themes Improper Input Validation Leads to Arbitrary ActivityImproper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. |
|
| CVE-2026-21072 | Aug 10, 2026 |
Samsung libsavsvc VC1 Codec OOB Write via Improper Input ValidationImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21071 | Aug 10, 2026 |
Samsung Mobile libsavsvc.so MPEG4 Codec OOB Write VulnerabilityImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21070 | Aug 10, 2026 |
Improper Input Validation in Samsung Message Enables Physical AttackImproper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. |
|
| CVE-2026-21069 | Aug 10, 2026 |
Samsung Mobile libsavsvc.so VC1 OOB Write via Numeric ConversionIncorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21068 | Aug 10, 2026 |
Stack-overflow in libril_sem.so (Android RIL) allows local code execStack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. |
|
| CVE-2026-21067 | Aug 10, 2026 |
Samsung libsmsd.so OOB Write via Improper Input ValidationImproper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21066 | Aug 10, 2026 |
Samsung Mobile libcodec2_sec_flacdec.so OOB Write via Improper Input ValidationImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|