Samsung Mobile Devices

34 known vulnerabilities in Samsung Mobile Devices, 5 critical, 13 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2025-21043 CVSS 9.8 critical · actively exploited Samsung Mobile Devices Out-of-Bounds Write Vulnerability
  • CVE-2025-21042 CVSS 9.8 critical · actively exploited Samsung Mobile Devices Out-of-Bounds Write Vulnerability
  • CVE-2023-21492 CVSS 4.4 medium · actively exploited Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
  • CVE-2022-22265 CVSS 7.8 high · actively exploited Samsung Mobile Devices Use-After-Free Vulnerability
  • CVE-2021-25489 CVSS 5.5 medium · actively exploited Samsung Mobile Devices Improper Input Validation Vulnerability
  • CVE-2021-25487 CVSS 7.8 high · actively exploited Samsung Mobile Devices Out-of-Bounds Read Vulnerability
  • CVE-2021-25395 CVSS 6.4 medium · actively exploited Samsung Mobile Devices Race Condition Vulnerability
  • CVE-2021-25394 CVSS 6.4 medium · actively exploited Samsung Mobile Devices Race Condition Vulnerability
  • CVE-2021-25372 CVSS 6.7 medium · actively exploited Samsung Mobile Devices Improper Boundary Check Vulnerability
  • CVE-2021-25371 CVSS 6.7 medium · actively exploited Samsung Mobile Devices Unspecified Vulnerability

Latest vulnerabilities

  • CVE-2026-21140 CVSS 6.9 medium Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
  • CVE-2026-21104 CVSS 7.1 high Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary…
  • CVE-2026-21103 CVSS 6.8 medium Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
  • CVE-2026-21102 CVSS 9.3 critical Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
  • CVE-2026-21101 CVSS 8.4 high Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute…
  • CVE-2026-21100 CVSS 6.9 medium Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
  • CVE-2026-21099 CVSS 5.1 medium Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
  • CVE-2026-21098 CVSS 6.9 medium Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC…
  • CVE-2026-21097 CVSS 4.6 medium Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch…
  • CVE-2026-21096 CVSS 9.2 critical Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute…
  • CVE-2026-21095 CVSS 9.2 critical Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute…
  • CVE-2026-21094 CVSS 6.1 medium Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.
  • CVE-2026-21093 CVSS 5.6 medium Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds…
  • CVE-2026-21092 CVSS 8.8 high Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
  • CVE-2026-21091 CVSS 4.8 medium Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
  • CVE-2026-21090 CVSS 4.8 medium Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
  • CVE-2026-21089 CVSS 6.9 medium Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write…
  • CVE-2026-21088 CVSS 6.9 medium Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to…
  • CVE-2026-21087 CVSS 8.6 high Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server…
  • CVE-2026-21086 CVSS 4.8 medium Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.
  • CVE-2026-21085 CVSS 8.4 high Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
  • CVE-2025-21043 CVSS 9.8 critical · actively exploited Samsung Mobile Devices Out-of-Bounds Write Vulnerability
  • CVE-2025-21042 CVSS 9.8 critical · actively exploited Samsung Mobile Devices Out-of-Bounds Write Vulnerability
  • CVE-2023-21492 CVSS 4.4 medium · actively exploited Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
  • CVE-2022-22265 CVSS 7.8 high · actively exploited Samsung Mobile Devices Use-After-Free Vulnerability
  • CVE-2021-25489 CVSS 5.5 medium · actively exploited Samsung Mobile Devices Improper Input Validation Vulnerability
  • CVE-2021-25487 CVSS 7.8 high · actively exploited Samsung Mobile Devices Out-of-Bounds Read Vulnerability
  • CVE-2021-25395 CVSS 6.4 medium · actively exploited Samsung Mobile Devices Race Condition Vulnerability
  • CVE-2021-25394 CVSS 6.4 medium · actively exploited Samsung Mobile Devices Race Condition Vulnerability
  • CVE-2021-25372 CVSS 6.7 medium · actively exploited Samsung Mobile Devices Improper Boundary Check Vulnerability