Samsung
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Samsung product.
RSS Feeds for Samsung security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Samsung products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Samsung Sorted by Most Security Vulnerabilities since 2018
Recent Samsung Security Advisories
| Advisory | Title | Published |
|---|---|---|
| SMR-Aug-2026 | Samsung Mobile Security Maintenance Release SMR-Aug-2026 | August 4, 2026 |
| SMR-Jul-2026 | Samsung Mobile Security Maintenance Release SMR-Jul-2026 | July 7, 2026 |
| SMR-Jun-2026 | Samsung Mobile Security Maintenance Release SMR-Jun-2026 | June 2, 2026 |
| SMR-May-2026 | Samsung Mobile Security Maintenance Release SMR-May-2026 | May 6, 2026 |
| SMR-Apr-2026 | Samsung Mobile Security Maintenance Release SMR-Apr-2026 | April 7, 2026 |
| SMR-Mar-2026 | Samsung Mobile Security Maintenance Release SMR-Mar-2026 | March 3, 2026 |
| SMR-Feb-2026 | Samsung Mobile Security Maintenance Release SMR-Feb-2026 | February 3, 2026 |
| SMR-Jan-2026 | Samsung Mobile Security Maintenance Release SMR-Jan-2026 | January 6, 2026 |
| SMR-Dec-2025 | Samsung Mobile Security Maintenance Release SMR-Dec-2025 | December 2, 2025 |
| SMR-Nov-2025 | Samsung Mobile Security Maintenance Release SMR-Nov-2025 | November 11, 2025 |
Known Exploited Samsung Vulnerabilities
The following Samsung vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Samsung MagicINFO 9 Server Path Traversal Vulnerability |
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. CVE-2024-7399 Exploit Probability: 91.9% |
April 24, 2026 |
| Samsung Mobile Devices Out-of-Bounds Write Vulnerability |
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. CVE-2025-21042 Exploit Probability: 33.1% |
November 10, 2025 |
| Samsung Mobile Devices Out-of-Bounds Write Vulnerability |
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. CVE-2025-21043 Exploit Probability: 1.9% |
October 2, 2025 |
| Samsung MagicINFO 9 Server Path Traversal Vulnerability |
Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. CVE-2025-4632 Exploit Probability: 24.4% |
May 22, 2025 |
| Samsung Mobile Devices Use-After-Free Vulnerability |
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. CVE-2022-22265 Exploit Probability: 0.4% |
September 18, 2023 |
| Samsung Mobile Devices Out-of-Bounds Read Vulnerability |
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. CVE-2021-25487 Exploit Probability: 0.6% |
June 29, 2023 |
| Samsung Mobile Devices Improper Input Validation Vulnerability |
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. CVE-2021-25489 Exploit Probability: 0.5% |
June 29, 2023 |
| Samsung Mobile Devices Race Condition Vulnerability |
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. CVE-2021-25394 Exploit Probability: 0.4% |
June 29, 2023 |
| Samsung Mobile Devices Race Condition Vulnerability |
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. CVE-2021-25395 Exploit Probability: 0.4% |
June 29, 2023 |
| Samsung Mobile Devices Unspecified Vulnerability |
Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. CVE-2021-25371 Exploit Probability: 0.8% |
June 29, 2023 |
| Samsung Mobile Devices Improper Boundary Check Vulnerability |
Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. CVE-2021-25372 Exploit Probability: 0.8% |
June 29, 2023 |
| Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability |
Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass. CVE-2023-21492 Exploit Probability: 2.6% |
May 19, 2023 |
| Samsung Mobile Devices Improper Access Control Vulnerability |
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. CVE-2021-25337 Exploit Probability: 2.8% |
November 8, 2022 |
| Samsung Mobile Devices Improper Access Control Vulnerability |
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. CVE-2021-25369 Exploit Probability: 1.1% |
November 8, 2022 |
| Samsung Mobile Devices Memory Corruption Vulnerability |
Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. CVE-2021-25370 Exploit Probability: 0.9% |
November 8, 2022 |
The vulnerability CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Samsung vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 132 vulnerabilities in Samsung with an average score of 6.5 out of ten. Last year, in 2025 Samsung had 191 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Samsung in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.20.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 132 | 6.49 |
| 2025 | 191 | 6.29 |
| 2024 | 230 | 5.95 |
| 2023 | 236 | 6.33 |
| 2022 | 147 | 5.66 |
| 2021 | 73 | 5.73 |
| 2020 | 10 | 8.10 |
| 2019 | 7 | 7.00 |
| 2018 | 20 | 7.71 |
It may take a day or so for new Samsung vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Samsung Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-19588 | Aug 12, 2026 |
Samsung rlottie IntegerOverflowBufferOverflowInteger Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. |
|
| CVE-2026-19587 | Aug 12, 2026 |
Samsung rlottie Uncontrolled Resource Consumption: Excessive AllocationUncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. |
|
| CVE-2026-21084 | Aug 10, 2026 |
SmartThings <1.8.47.24 Improper Access Local Attacker Sensitive InfoImproper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. |
|
| CVE-2026-21083 | Aug 10, 2026 |
Smart Switch <3.7.72.6 Improper Input Validation Allows Adjacent AccessImproper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. |
|
| CVE-2026-21082 | Aug 10, 2026 |
Samsung Health <7.0.0 RPT: Relative Path Traversal Local Privileged AccessRelative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
|
| CVE-2026-21081 | Aug 10, 2026 |
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.xImproper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. |
|
| CVE-2026-21080 | Aug 10, 2026 |
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. |
|
| CVE-2026-21079 | Aug 10, 2026 |
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. |
|
| CVE-2026-21078 | Aug 10, 2026 |
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. |
|
| CVE-2026-21077 | Aug 10, 2026 |
Incorrect authorization in Samsung Health prior to version 7.0.0Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
|
| CVE-2026-21076 | Aug 10, 2026 |
Incorrect authorization in Samsung Health prior to version 7.0.0Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
|
| CVE-2026-21075 | Aug 10, 2026 |
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. |
|
| CVE-2026-21074 | Aug 10, 2026 |
Incorrect default permissions in Bixby prior to version 4.0.86.0Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege. |
|
| CVE-2026-21073 | Aug 10, 2026 |
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. |
|
| CVE-2026-21072 | Aug 10, 2026 |
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21071 | Aug 10, 2026 |
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21070 | Aug 10, 2026 |
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. |
|
| CVE-2026-21069 | Aug 10, 2026 |
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21068 | Aug 10, 2026 |
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. |
|
| CVE-2026-21067 | Aug 10, 2026 |
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21066 | Aug 10, 2026 |
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21065 | Aug 10, 2026 |
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
|
| CVE-2026-21064 | Aug 10, 2026 |
Improper access control in Weaver prior to SMR Aug-2026 Release 1Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. |
|
| CVE-2026-21063 | Aug 10, 2026 |
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. |
|
| CVE-2026-21062 | Aug 10, 2026 |
Auth Bypass in SemClipboardService: Local Clipboard Data AccessAuthorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. |
|
| CVE-2026-21061 | Aug 10, 2026 |
Samsung Dialer Improper Input Validation Enables Remote SIM AccessImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. |
|
| CVE-2026-21060 | Aug 10, 2026 |
Samsung Contacts Input Validation Flaw Enables Physical Attack, Cross-Profile Data AccessImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. |
|
| CVE-2026-21059 | Aug 10, 2026 |
Samsung Contacts: Improper export enables local file delete (CVE-2026-21059)Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. |
|
| CVE-2026-21058 | Aug 10, 2026 |
Samsung Contacts Improper Input Validation Allows Local File DeletionImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. |
|
| CVE-2026-18772 | Aug 04, 2026 |
Samsung Open Source rlottie IEV: Improper Validation Enables Oversized PayloadsImproperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. |
|
| CVE-2026-21047 | Jul 28, 2026 |
SamsungMobile ImsService OOB write leads to remote code execOut-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. |
|
| CVE-2026-21057 | Jul 10, 2026 |
Samsung Pass <5.2.10.3 Improper Input Validation Enables Local OOB WriteImproper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory. |
|
| CVE-2026-21056 | Jul 10, 2026 |
Samsung Health 7.00.0.106 Improper Auth: Local Access to Connected Device InfoImproper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information. |
|
| CVE-2026-21055 | Jul 10, 2026 |
Samsung Bixby <4.0.70.8 Improper exported component leads to local command execImproper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege. |
|
| CVE-2026-21054 | Jul 10, 2026 |
InputSharing Improper Component Export (Android) <2.7.01.4 Local ExploitImproper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data. |
|
| CVE-2026-21053 | Jul 10, 2026 |
Samsung Email <6.2.13.1 Improper Input Validation Allows Local File CreationImproper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox. |
|
| CVE-2026-21052 | Jul 10, 2026 |
CVE-2026-21052: Path Traversal in SemClipboardService (Samsung Mobile)Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. |
|
| CVE-2026-21051 | Jul 10, 2026 |
Samsung Mobile WLAN Local Priv Escalation via TencentWifiSecurity MisconfigIncorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings. |
|
| CVE-2026-21050 | Jul 10, 2026 |
Improper Access Control in SmartThingsKit - Local Attacker AccessImproper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. |
|
| CVE-2026-21049 | Jul 10, 2026 |
Samsung Mobile libpadm.so OOB Write Enables Local Code ExecOut-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code. |
|
| CVE-2026-21048 | Jul 10, 2026 |
Samsung Android DNG OOB Write in libimagecodec.media.quram.soOut-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. |
|
| CVE-2026-21046 | Jul 10, 2026 |
TOCTOU Race in Samsung FabricKeymaster Trustlet Enables Local Privileged Code ExecTime-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code. |
|
| CVE-2026-21045 | Jul 10, 2026 |
Samsung libimagecodec.media.quram OOB write in TIFF parserOut-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. |
|
| CVE-2026-21044 | Jul 10, 2026 |
Local Persistence Bypass via Improper Auth in KnoxGuardManagerImproper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. |
|
| CVE-2026-21043 | Jul 10, 2026 |
Path Traversal in Samsung Android Wallpaper Service Exposes System FilesPath traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege. |
|
| CVE-2026-21042 | Jul 10, 2026 |
Samsung Android libsavsac.so OOB Write RCE VulnerabilityOut-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code. |
|
| CVE-2026-21041 | Jul 10, 2026 |
Improper Access Control in Samsung SE Agent ServiceImproper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. |
|
| CVE-2026-21040 | Jul 10, 2026 |
Improper Access Control in IAFDService Allows Local Privileged UseImproper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs. |
|
| CVE-2026-21039 | Jul 10, 2026 |
Samsung Mobile Settings Improper ACL in Theft-Protection ConfigImproper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings. |
|
| CVE-2026-21038 | Jun 05, 2026 |
Samsung Android USB Driver for Windows 1.9.5.0 Improper Validation OOB MemoryImproper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. |
|