Samsung Mobile Devices Samsung Mobile Devices

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Samsung Mobile Devices.

By the Year

In 2026 there have been 73 vulnerabilities in Samsung Mobile Devices with an average score of 5.9 out of ten. Last year, in 2025 Samsung Mobile Devices had 29 security vulnerabilities published. That is, 44 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.27.




Year Vulnerabilities Average Score
2026 73 5.87
2025 29 5.60
2024 0 0.00
2023 1 4.40
2022 1 5.00
2021 9 5.81

It may take a day or so for new Samsung Mobile Devices vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Samsung Mobile Devices Security Vulnerabilities

Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1
CVE-2026-21073 5.2 - Medium - August 10, 2026

Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1
CVE-2026-21072 5.1 - Medium - August 10, 2026

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper Input Validation

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1
CVE-2026-21071 5.1 - Medium - August 10, 2026

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper Input Validation

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1
CVE-2026-21070 5.1 - Medium - August 10, 2026

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

Improper Input Validation

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1
CVE-2026-21069 5.1 - Medium - August 10, 2026

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Incorrect Conversion between Numeric Types

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1
CVE-2026-21068 8.4 - High - August 10, 2026

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

Stack Overflow

Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1
CVE-2026-21067 5.1 - Medium - August 10, 2026

Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1
CVE-2026-21066 5.1 - Medium - August 10, 2026

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper Input Validation

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1
CVE-2026-21065 4.4 - Medium - August 10, 2026

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper Input Validation

Improper access control in Weaver prior to SMR Aug-2026 Release 1
CVE-2026-21064 7 - High - August 10, 2026

Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

Authorization

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1
CVE-2026-21063 6.8 - Medium - August 10, 2026

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

Improper Export of Android Application Components

Auth Bypass in SemClipboardService: Local Clipboard Data Access
CVE-2026-21062 4.8 - Medium - August 10, 2026

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

Improper Authorization in Handler for Custom URL Scheme

Samsung Dialer Improper Input Validation Enables Remote SIM Access
CVE-2026-21061 6 - Medium - August 10, 2026

Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

Improper Input Validation

Samsung Contacts Input Validation Flaw Enables Physical Attack, Cross-Profile Data Access
CVE-2026-21060 6.7 - Medium - August 10, 2026

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

Improper Input Validation

Samsung Contacts: Improper export enables local file delete (CVE-2026-21059)
CVE-2026-21059 6.9 - Medium - August 10, 2026

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

Improper Export of Android Application Components

Samsung Contacts Improper Input Validation Allows Local File Deletion
CVE-2026-21058 6.9 - Medium - August 10, 2026

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

Improper Input Validation

SamsungMobile ImsService OOB write leads to remote code exec
CVE-2026-21047 - July 28, 2026

Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.

Memory Corruption

CVE-2026-21052: Path Traversal in SemClipboardService (Samsung Mobile)
CVE-2026-21052 - July 10, 2026

Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.

Samsung Mobile WLAN Local Priv Escalation via TencentWifiSecurity Misconfig
CVE-2026-21051 - July 10, 2026

Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.

Improper Access Control in SmartThingsKit - Local Attacker Access
CVE-2026-21050 - July 10, 2026

Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.

Samsung Mobile libpadm.so OOB Write Enables Local Code Exec
CVE-2026-21049 - July 10, 2026

Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.

Samsung Android DNG OOB Write in libimagecodec.media.quram.so
CVE-2026-21048 - July 10, 2026

Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.

TOCTOU Race in Samsung FabricKeymaster Trustlet Enables Local Privileged Code Exec
CVE-2026-21046 - July 10, 2026

Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Samsung libimagecodec.media.quram OOB write in TIFF parser
CVE-2026-21045 - July 10, 2026

Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.

Local Persistence Bypass via Improper Auth in KnoxGuardManager
CVE-2026-21044 - July 10, 2026

Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

Path Traversal in Samsung Android Wallpaper Service Exposes System Files
CVE-2026-21043 - July 10, 2026

Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.

Samsung Android libsavsac.so OOB Write RCE Vulnerability
CVE-2026-21042 - July 10, 2026

Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.

Improper Access Control in Samsung SE Agent Service
CVE-2026-21041 - July 10, 2026

Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.

Improper Access Control in IAFDService Allows Local Privileged Use
CVE-2026-21040 - July 10, 2026

Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.

Samsung Mobile Settings Improper ACL in Theft-Protection Config
CVE-2026-21039 - July 10, 2026

Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.

AppBlock Improper Authorization for Local Arbitrary Activity
CVE-2026-21031 - June 05, 2026

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

MediaTek Audio HAL Access Control Bypass (CVE-2026-21030)
CVE-2026-21030 - June 05, 2026

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

Android Galaxy Editing Service Misexport Enables Local Privilege Escalation
CVE-2026-21029 - June 05, 2026

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

Improper ACL in Samsung Android AuditLogService Allows Local Info Leak
CVE-2026-21028 - June 05, 2026

Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

Android ImsSettings Improper Export Enables Local Logging Exploit
CVE-2026-21027 - June 05, 2026

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

SpriteWallpaper Android App Improper Exposed Components Allow Local Info Access
CVE-2026-21026 - June 05, 2026

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

Samsung Telephony PRIVILEGE Escalation via incorrect permission assignment
CVE-2026-21025 - June 05, 2026

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

Android: SecTelephonyProvider Privilege Escalation via Improper Access Controls
CVE-2026-21017 - June 05, 2026

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

Samsung Routines Improper Insufficient Permissions Local Info Disclosure
CVE-2026-21022 - May 13, 2026

Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

Samsung Mobile Routines Improper Input Validation Enables Priv Escalation
CVE-2026-21021 - May 13, 2026

Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.

Android OmaCP Improper Export Enables Local Privilege Escalation
CVE-2026-21020 - May 13, 2026

Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.

Galaxy Watch: Input Validation Flaw in FacAtFunction Enables Arbitrary Code
CVE-2026-21019 - May 13, 2026

Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.

OOB write in SveService permits local privileged exec (Samsung)
CVE-2026-21018 - May 13, 2026

Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Android LocationManager Privilege Escalation via Incorrect Assignment
CVE-2026-21016 - May 13, 2026

Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

FactoryCamera default permission flaw exposes unique ID
CVE-2026-21015 - May 13, 2026

Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.

Android PackageManagerService Data Auth Verification Flaw
CVE-2026-21023 - April 29, 2026

Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

Samsung Mobile Retail Mode Improper Input Validation for Privileged Escalation
CVE-2026-21010 6.6 - Medium - April 13, 2026

Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.

Samsung S Share Sensitive Info Leak via Adjacent Attack
CVE-2026-21008 - April 13, 2026

Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.

Samsung AODManager LFI: Privileged Local File Creation
CVE-2026-21012 - April 13, 2026

External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

Samsung Android Bluetooth Privilege Assignment Bypass in Maintenance Mode
CVE-2026-21011 - April 13, 2026

Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Samsung Mobile Devices or by Samsung? Click the Watch button to subscribe.

Samsung
Vendor

subscribe