Samsung Samsung

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Samsung product.

RSS Feeds for Samsung security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Samsung products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Samsung Sorted by Most Security Vulnerabilities since 2018

Samsung Android351 vulnerabilities

Samsung Mobile Devices134 vulnerabilities

Samsung Notes62 vulnerabilities

Samsung Exynos57 vulnerabilities

Samsung Galaxy Store31 vulnerabilities

Samsung Internet26 vulnerabilities

Samsung Magicinfo 9 Server24 vulnerabilities

Samsung Account23 vulnerabilities

Samsung Smartthings20 vulnerabilities

Samsung Pass16 vulnerabilities

Samsung Health15 vulnerabilities

Samsung Email14 vulnerabilities

Samsung Blockchain Keystore12 vulnerabilities

Samsung Rlottie11 vulnerabilities

Samsung Pass10 vulnerabilities

Samsung Cloud9 vulnerabilities

Samsung Members9 vulnerabilities

Samsung Email9 vulnerabilities

Samsung Exynos 1330 Firmware8 vulnerabilities

Samsung Gallery8 vulnerabilities

Samsung Flow7 vulnerabilities

Samsung Blockchain Keystore7 vulnerabilities

Samsung Exynos 1280 Firmware6 vulnerabilities

Samsung Wear Os6 vulnerabilities

Samsung Flow6 vulnerabilities

Samsung Bixby5 vulnerabilities

Samsung Exynos 850 Firmware5 vulnerabilities

Samsung Pay4 vulnerabilities

Samsung Magician4 vulnerabilities

Samsung Update3 vulnerabilities

Samsung Exynos 1380 Firmware3 vulnerabilities

Samsung Easysetup2 vulnerabilities

Samsung Escargot2 vulnerabilities

Samsung Exynos 1080 Firmware2 vulnerabilities

Samsung Exynos 1580 Firmware2 vulnerabilities

Samsung Exynos 2200 Firmware2 vulnerabilities

Samsung Galaxy S24 Firmware2 vulnerabilities

Samsung Uphelper Library2 vulnerabilities

Samsung Group Sharing2 vulnerabilities

Samsung Assistant1 vulnerability

Samsung Dex1 vulnerability

Samsung Galaxystore1 vulnerability

Recent Samsung Security Advisories

Advisory Title Published
SMR-Sep-2026 Samsung Mobile Security Maintenance Release SMR-Sep-2026 September 8, 2026
SMR-Aug-2026 Samsung Mobile Security Maintenance Release SMR-Aug-2026 August 4, 2026
SMR-Jul-2026 Samsung Mobile Security Maintenance Release SMR-Jul-2026 July 7, 2026
SMR-Jun-2026 Samsung Mobile Security Maintenance Release SMR-Jun-2026 June 2, 2026
SMR-May-2026 Samsung Mobile Security Maintenance Release SMR-May-2026 May 6, 2026
SMR-Apr-2026 Samsung Mobile Security Maintenance Release SMR-Apr-2026 April 7, 2026
SMR-Mar-2026 Samsung Mobile Security Maintenance Release SMR-Mar-2026 March 3, 2026
SMR-Feb-2026 Samsung Mobile Security Maintenance Release SMR-Feb-2026 February 3, 2026
SMR-Jan-2026 Samsung Mobile Security Maintenance Release SMR-Jan-2026 January 6, 2026
SMR-Dec-2025 Samsung Mobile Security Maintenance Release SMR-Dec-2025 December 2, 2025

Known Exploited Samsung Vulnerabilities

The following Samsung vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Samsung MagicINFO 9 Server Path Traversal Vulnerability Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
CVE-2024-7399 Exploit Probability: 91.9%
April 24, 2026
Samsung Mobile Devices Out-of-Bounds Write Vulnerability Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-21042 Exploit Probability: 33.2%
November 10, 2025
Samsung Mobile Devices Out-of-Bounds Write Vulnerability Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
CVE-2025-21043 Exploit Probability: 2.1%
October 2, 2025
Samsung MagicINFO 9 Server Path Traversal Vulnerability Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.
CVE-2025-4632 Exploit Probability: 24.3%
May 22, 2025
Samsung Mobile Devices Use-After-Free Vulnerability Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
CVE-2022-22265 Exploit Probability: 0.4%
September 18, 2023
Samsung Mobile Devices Out-of-Bounds Read Vulnerability Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.
CVE-2021-25487 Exploit Probability: 0.6%
June 29, 2023
Samsung Mobile Devices Improper Input Validation Vulnerability Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
CVE-2021-25489 Exploit Probability: 0.5%
June 29, 2023
Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
CVE-2021-25394 Exploit Probability: 0.4%
June 29, 2023
Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
CVE-2021-25395 Exploit Probability: 0.4%
June 29, 2023
Samsung Mobile Devices Unspecified Vulnerability Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.
CVE-2021-25371 Exploit Probability: 0.8%
June 29, 2023
Samsung Mobile Devices Improper Boundary Check Vulnerability Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.
CVE-2021-25372 Exploit Probability: 0.8%
June 29, 2023
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.
CVE-2023-21492 Exploit Probability: 2.6%
May 19, 2023
Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.
CVE-2021-25337 Exploit Probability: 2.8%
November 8, 2022
Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.
CVE-2021-25369 Exploit Probability: 1.1%
November 8, 2022
Samsung Mobile Devices Memory Corruption Vulnerability Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.
CVE-2021-25370 Exploit Probability: 0.9%
November 8, 2022

The vulnerability CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Samsung vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 183 vulnerabilities in Samsung with an average score of 6.0 out of ten. Last year, in 2025 Samsung had 191 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Samsung in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.28




Year Vulnerabilities Average Score
2026 183 6.00
2025 191 6.29
2024 230 5.95
2023 236 6.33
2022 147 5.66
2021 73 5.73
2020 10 8.10
2019 7 7.00
2018 20 7.71

It may take a day or so for new Samsung vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Samsung Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-21140 Oct 02, 2026
CVE-2026-21140: Samsung ManagedProvision Improper AC Enables Local App Install Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
Samsung Mobile Devices
CVE-2026-91826 Sep 15, 2026
Samsung rLottie Stack Overflow Vulnerability in Vector Rendering Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.
Rlottie
CVE-2023-37366 Sep 14, 2026
Samsung Exynos: SM Task Loop Exit Condition Improper Handling An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.
Exynos 850 Firmware
CVE-2026-33970 Sep 14, 2026
Samsung Exynos 5G Baseband NR RRC null ptr deref CVE-2026-33970 An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.
Exynos 850 Firmware
CVE-2026-33968 Sep 14, 2026
Samsung Exynos Cam Driver TOCTOU OOB An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.
Exynos 1330 Firmware
CVE-2026-33967 Sep 14, 2026
Out-of-Bounds Array Access in Samsung Exynos Camera Driver An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.
Exynos 1330 Firmware
CVE-2026-33966 Sep 14, 2026
Samsung Exynos camera driver sensitive info debug leak An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.
Exynos 1330 Firmware
CVE-2026-23787 Sep 14, 2026
Use-After-Free in Samsung Exynos DRM HDR Driver Causes Kernel Crash An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.
Exynos 1280 Firmware
CVE-2026-23792 Sep 14, 2026
Samsung Exynos Baseband Crash via NR RRC Unauth Setup An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.
Exynos 1080 Firmware
CVE-2026-23791 Sep 14, 2026
Samsung Exynos DPU Driver OOB Write Priv Escalation An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.
Exynos 1280 Firmware
CVE-2026-23790 Sep 14, 2026
Samsung Exynos DPU Driver Double-Free Kernel Memory Corruption (CVE-2026-23790) An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.
Exynos 1280 Firmware
CVE-2026-23789 Sep 14, 2026
Samsung Exynos MFC Encoder Driver Double-Free Kernel Vulnerability An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.
Exynos 850 Firmware
CVE-2026-23788 Sep 14, 2026
Samsung Exynos DRM HDR Driver Heap Overflow An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
Exynos 1280 Firmware
CVE-2026-33957 Sep 14, 2026
Out-of-Bounds Read/Write in CustOS Driver on Samsung Exynos 1580 An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.
Exynos 1580 Firmware
CVE-2026-33956 Sep 14, 2026
Samsung Exynos Camera Driver OOB Write via Sysfs An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.
Exynos 1330 Firmware
CVE-2026-23793 Sep 14, 2026
Out-of-Bounds Mem Access in Samsung Exynos GDC Driver An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.
Exynos 1330 Firmware
CVE-2026-33964 Sep 14, 2026
Exynos 1580/2500 Camera Driver Pointer Deref - Info Disclosure/DoS An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.
Exynos 1580 Firmware
CVE-2026-33963 Sep 14, 2026
Exynos Camera Driver Stack Overflow Causes DoS An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
Exynos 1330 Firmware
CVE-2026-33962 Sep 14, 2026
Exynos WiFi Netlink OOB Read CVE-2026-33962 An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.
Exynos 850 Firmware
CVE-2026-33960 Sep 14, 2026
Exynos WiFi Driver Ioctl OOB Write DoS An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).
Exynos 1330 Firmware
CVE-2026-23786 Sep 14, 2026
Exynos DRM HDR Driver TOCTOU Race Causing Heap Overflow Crash An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.
Exynos 1280 Firmware
CVE-2024-53922 Sep 13, 2026
Exynos Auto Buffer Queue Driver DoS via Missing Length Check An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
Exynos
CVE-2026-21113 Sep 09, 2026
Samsung Visual Voicemail <20.1.00.05: Improper Export (Local Call) Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
Email
CVE-2026-21112 Sep 09, 2026
Samsung Tips Improper Input Validation Allows Local Activity Launch (Android 17) Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
CVE-2026-21111 Sep 09, 2026
SA-2026-21111 OOB write in libsthmbc.so before One UI 8.5 Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.
CVE-2026-21110 Sep 09, 2026
OOB write in libsavscmn.so before OneUI 8.5 enables local code exec Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.
CVE-2026-21109 Sep 09, 2026
Android Watch 17 Watch Plugin Improper Access Control Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.
CVE-2026-21108 Sep 09, 2026
Android Bixby Touch Improper Component Export (pre4.3.01.17) Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.
Bixby
CVE-2026-21107 Sep 09, 2026
Samsung Notes OOB Write v<4.4.45.5 (Local) Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.
Notes
CVE-2026-21106 Sep 09, 2026
Samsung Cloud Assistant <9.0.5 Intent Mis-Verification Allows Local Disable Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Cloud
CVE-2026-21105 Sep 09, 2026
Android Collection Improper Access Control <1.0.1.14 (15) / 2.0.02.7 (16) Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
CVE-2026-21104 Sep 09, 2026
Heap Buffer Overflow in Samsung KnoxVault Trustlet (CVE-2026-21104) Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Samsung Mobile Devices
CVE-2026-21103 Sep 09, 2026
GalaxyDiagnostics Path Traversal Allows Physical Attackers to Read System Files Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
Samsung Mobile Devices
CVE-2026-21102 Sep 09, 2026
DualDAR UAF Allows Root Code Exec on Samsung Mobile Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
Samsung Mobile Devices
CVE-2026-21101 Sep 09, 2026
DualDAR driver input validation flaw allows local privilege escalation Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.
Samsung Mobile Devices
CVE-2026-21100 Sep 09, 2026
Samsung SystemUI Improper Access Control: Local Attacker Arbitrary Activity Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
Samsung Mobile Devices
CVE-2026-21099 Sep 09, 2026
Samsung SettingsProvider Improper Access Control (CVE-2026-21099) Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
Samsung Mobile Devices
CVE-2026-21098 Sep 09, 2026
CVE-2026-21098: Improper Access Control in Samsung Link to Windows Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.
Samsung Mobile Devices
CVE-2026-21097 Sep 09, 2026
Android Local Privilege Escalation via ActivityTaskManagerService Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
Samsung Mobile Devices
CVE-2026-21096 Sep 09, 2026
Heap Overflow in Samsung libimagecodec JPEG Decoder Enables RCE Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
Samsung Mobile Devices
CVE-2026-21095 Sep 09, 2026
Heap Buffer Overflow in libimagecodec.quram.so DNG Decoder (Samsung Android) Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
Samsung Mobile Devices
CVE-2026-21094 Sep 09, 2026
wpa_supplicant OOB Write via Improper Input Validation Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.
Samsung Mobile Devices
CVE-2026-21093 Sep 09, 2026
PROCA trustlet: Stack buffer overflow allows local privilege escalation on Samsung Mobile Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Samsung Mobile Devices
CVE-2026-21092 Sep 09, 2026
Android ImsService Path Traversal Enables System-Privileged Image Creation Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
Samsung Mobile Devices
CVE-2026-21091 Sep 09, 2026
Samsung Mobile libcodec2secevrcdec.so OOB Write (CVE-2026-21091) Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Mobile Devices
CVE-2026-21090 Sep 09, 2026
Samsung libsaviextractor.so OOB write allows local memory corruption Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Mobile Devices
CVE-2026-21089 Sep 09, 2026
Samsung Mobile libsubextractor SO OOB Write via Input Validation Flaw Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Mobile Devices
CVE-2026-21088 Sep 09, 2026
Improper Input Validation in libsubextractor.so OOB Write Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Mobile Devices
CVE-2026-21087 Sep 09, 2026
Samsung Android libmdnie.so OOB Write Enables System Privilege Escalation Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.
Samsung Mobile Devices
CVE-2026-21086 Sep 09, 2026
Samsung Mobile ProxyHandler Local Access Unauthorized Access CVE-2026-21086 Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.
Samsung Mobile Devices
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.