Samsung Mobile Devices
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Samsung Mobile Devices.
By the Year
In 2026 there have been 93 vulnerabilities in Samsung Mobile Devices with an average score of 6.5 out of ten. Last year, in 2025 Samsung Mobile Devices had 29 security vulnerabilities published. That is, 64 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.88.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 93 | 6.48 |
| 2025 | 29 | 5.60 |
| 2024 | 0 | 0.00 |
| 2023 | 1 | 4.40 |
| 2022 | 1 | 5.00 |
| 2021 | 9 | 5.81 |
It may take a day or so for new Samsung Mobile Devices vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Samsung Mobile Devices Security Vulnerabilities
Heap Buffer Overflow in Samsung KnoxVault Trustlet (CVE-2026-21104)
CVE-2026-21104
7.1 - High
- September 09, 2026
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
GalaxyDiagnostics Path Traversal Allows Physical Attackers to Read System Files
CVE-2026-21103
6.8 - Medium
- September 09, 2026
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
DualDAR UAF Allows Root Code Exec on Samsung Mobile
CVE-2026-21102
9.3 - Critical
- September 09, 2026
Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
DualDAR driver input validation flaw allows local privilege escalation
CVE-2026-21101
8.4 - High
- September 09, 2026
Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.
Samsung SystemUI Improper Access Control: Local Attacker Arbitrary Activity
CVE-2026-21100
6.9 - Medium
- September 09, 2026
Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
Samsung SettingsProvider Improper Access Control (CVE-2026-21099)
CVE-2026-21099
5.1 - Medium
- September 09, 2026
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21098: Improper Access Control in Samsung Link to Windows
CVE-2026-21098
6.9 - Medium
- September 09, 2026
Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.
Android Local Privilege Escalation via ActivityTaskManagerService
CVE-2026-21097
4.6 - Medium
- September 09, 2026
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
Heap Overflow in Samsung libimagecodec JPEG Decoder Enables RCE
CVE-2026-21096
9.2 - Critical
- September 09, 2026
Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
Heap Buffer Overflow in libimagecodec.quram.so DNG Decoder (Samsung Android)
CVE-2026-21095
9.2 - Critical
- September 09, 2026
Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
wpa_supplicant OOB Write via Improper Input Validation
CVE-2026-21094
6.1 - Medium
- September 09, 2026
Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.
PROCA trustlet: Stack buffer overflow allows local privilege escalation on Samsung Mobile
CVE-2026-21093
5.6 - Medium
- September 09, 2026
Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Android ImsService Path Traversal Enables System-Privileged Image Creation
CVE-2026-21092
8.8 - High
- September 09, 2026
Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
Samsung Mobile libcodec2secevrcdec.so OOB Write (CVE-2026-21091)
CVE-2026-21091
4.4 - Medium
- September 09, 2026
Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung libsaviextractor.so OOB write allows local memory corruption
CVE-2026-21090
4.4 - Medium
- September 09, 2026
Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Mobile libsubextractor SO OOB Write via Input Validation Flaw
CVE-2026-21089
6.9 - Medium
- September 09, 2026
Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Improper Input Validation in libsubextractor.so OOB Write
CVE-2026-21088
6.9 - Medium
- September 09, 2026
Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Android libmdnie.so OOB Write Enables System Privilege Escalation
CVE-2026-21087
8.6 - High
- September 09, 2026
Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.
Samsung Mobile ProxyHandler Local Access Unauthorized Access CVE-2026-21086
CVE-2026-21086
4.8 - Medium
- September 09, 2026
Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.
Keymaster Trustlet OOB Write (CVE-2026-21085) Samsung Android
CVE-2026-21085
8.4 - High
- September 09, 2026
Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Samsung Galaxy Themes Improper Input Validation Leads to Arbitrary Activity
CVE-2026-21073
5.2 - Medium
- August 10, 2026
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
Samsung libsavsvc VC1 Codec OOB Write via Improper Input Validation
CVE-2026-21072
5.1 - Medium
- August 10, 2026
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Improper Input Validation
Samsung Mobile libsavsvc.so MPEG4 Codec OOB Write Vulnerability
CVE-2026-21071
5.1 - Medium
- August 10, 2026
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Improper Input Validation
Improper Input Validation in Samsung Message Enables Physical Attack
CVE-2026-21070
5.1 - Medium
- August 10, 2026
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
Improper Input Validation
Samsung Mobile libsavsvc.so VC1 OOB Write via Numeric Conversion
CVE-2026-21069
5.1 - Medium
- August 10, 2026
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Incorrect Conversion between Numeric Types
Stack-overflow in libril_sem.so (Android RIL) allows local code exec
CVE-2026-21068
8.4 - High
- August 10, 2026
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
Stack Overflow
Samsung libsmsd.so OOB Write via Improper Input Validation
CVE-2026-21067
5.1 - Medium
- August 10, 2026
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Samsung Mobile libcodec2_sec_flacdec.so OOB Write via Improper Input Validation
CVE-2026-21066
5.1 - Medium
- August 10, 2026
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Improper Input Validation
Samsung Mobile libcodec2secqcelpdec.so OOB Write (CVE-2026-21065)
CVE-2026-21065
4.4 - Medium
- August 10, 2026
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Improper Input Validation
Local Improper Access Control in Samsung Weaver Causing Inoperability
CVE-2026-21064
7 - High
- August 10, 2026
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Authorization
Android AppLock Improper Export Enables Physical Bypass
CVE-2026-21063
6.8 - Medium
- August 10, 2026
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
Improper Export of Android Application Components
Auth Bypass in SemClipboardService: Local Clipboard Data Access
CVE-2026-21062
4.8 - Medium
- August 10, 2026
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
Improper Authorization in Handler for Custom URL Scheme
Samsung Dialer Improper Input Validation Enables Remote SIM Access
CVE-2026-21061
6 - Medium
- August 10, 2026
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
Improper Input Validation
Samsung Contacts Input Validation Flaw Enables Physical Attack, Cross-Profile Data Access
CVE-2026-21060
6.7 - Medium
- August 10, 2026
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
Improper Input Validation
Samsung Contacts: Improper export enables local file delete (CVE-2026-21059)
CVE-2026-21059
6.9 - Medium
- August 10, 2026
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Improper Export of Android Application Components
Samsung Contacts Improper Input Validation Allows Local File Deletion
CVE-2026-21058
6.9 - Medium
- August 10, 2026
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Improper Input Validation
SamsungMobile ImsService OOB write leads to remote code exec
CVE-2026-21047
- July 28, 2026
Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.
Memory Corruption
CVE-2026-21052: Path Traversal in SemClipboardService (Samsung Mobile)
CVE-2026-21052
- July 10, 2026
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
Samsung Mobile WLAN Local Priv Escalation via TencentWifiSecurity Misconfig
CVE-2026-21051
- July 10, 2026
Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.
Improper Access Control in SmartThingsKit - Local Attacker Access
CVE-2026-21050
- July 10, 2026
Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
Samsung Mobile libpadm.so OOB Write Enables Local Code Exec
CVE-2026-21049
- July 10, 2026
Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.
Samsung Android DNG OOB Write in libimagecodec.media.quram.so
CVE-2026-21048
- July 10, 2026
Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
TOCTOU Race in Samsung FabricKeymaster Trustlet Enables Local Privileged Code Exec
CVE-2026-21046
- July 10, 2026
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Samsung libimagecodec.media.quram OOB write in TIFF parser
CVE-2026-21045
- July 10, 2026
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
Local Persistence Bypass via Improper Auth in KnoxGuardManager
CVE-2026-21044
- July 10, 2026
Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
Path Traversal in Samsung Android Wallpaper Service Exposes System Files
CVE-2026-21043
- July 10, 2026
Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.
Samsung Android libsavsac.so OOB Write RCE Vulnerability
CVE-2026-21042
8.7 - High
- July 10, 2026
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.
Improper Access Control in Samsung SE Agent Service
CVE-2026-21041
- July 10, 2026
Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
Improper Access Control in IAFDService Allows Local Privileged Use
CVE-2026-21040
- July 10, 2026
Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.
Samsung Mobile Settings Improper ACL in Theft-Protection Config
CVE-2026-21039
- July 10, 2026
Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Samsung Mobile Devices or by Samsung? Click the Watch button to subscribe.