VulnSea

Samsung has 35 CVEs on record. Disclosure cadence is accelerating: 35 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 35. The median CVSS is 5.5 (medium), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-787 (9) and CWE-122 (4). Most affected products: android (15), Exynos 1330 firmware (7), Exynos 1280 firmware (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
35 prev 0

Products

  • android 15
  • Exynos 1330 firmware 7
  • Exynos 1280 firmware 5
  • Exynos 850 firmware 4
  • Exynos 1580 firmware 2
  • Exynos 1080 firmware 1
35
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

samsung vulnerabilities

CVEs affecting samsung, newest first. Open any entry for full detail, references, and exploit status.

35 CVEsRSS

CVE-2024-53922Medium· 5.7
1w ago

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.

SunlitSamsung · Exynos 8890 firmwareEPSS 0.16%via NVD
CVE-2026-33970Low· 3.5
1w ago

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NU…

SunlitSamsung · Exynos 850 firmwareEPSS 0.20%via NVD
CVE-2026-33967Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corrupt…

SunlitSamsung · Exynos 1330 firmwareEPSS 0.09%via NVD
CVE-2026-33966Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.

SunlitSamsung · Exynos 1330 firmwareEPSS 0.09%via NVD
CVE-2026-33964Medium· 6.4
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.

SunlitSamsung · Exynos 1580 firmwareEPSS 0.10%via NVD
CVE-2026-33963High· 7.5
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of serv…

TwilightSamsung · Exynos 1330 firmwareEPSS 0.11%via NVD
CVE-2026-33960Low· 2.8
1w ago

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation,…

SunlitSamsung · Exynos 1330 firmwareEPSS 0.09%via NVD
CVE-2026-33957Medium· 4.2
1w ago

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information…

SunlitSamsung · Exynos 1580 firmwareEPSS 0.09%via NVD
CVE-2026-33956Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.

SunlitSamsung · Exynos 1330 firmwareEPSS 0.09%via NVD
CVE-2026-23792Medium· 4.0
1w ago

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC …

SunlitSamsung · Exynos 1080 firmwareEPSS 0.13%via NVD
CVE-2026-23791Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mo…

SunlitSamsung · Exynos 1280 firmwareEPSS 0.09%via NVD
CVE-2026-23790Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffe…

SunlitSamsung · Exynos 1280 firmwareEPSS 0.09%via NVD
CVE-2026-23789High· 7.8
1w ago

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC en…

TwilightSamsung · Exynos 850 firmwareEPSS 0.11%via NVD
CVE-2026-23787Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.

SunlitSamsung · Exynos 1280 firmwareEPSS 0.09%via NVD
CVE-2026-23786Low· 2.8
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.

SunlitSamsung · Exynos 1280 firmwareEPSS 0.08%via NVD
CVE-2023-37366Low· 2.8
1w ago

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…

SunlitSamsung · Exynos 850 firmwareEPSS 0.09%via NVD
CVE-2026-33968Low· 2.8
1w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.

SunlitSamsung · Exynos 1330 firmwareEPSS 0.09%via NVD
CVE-2026-33962Low· 2.8
1w ago

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.

SunlitSamsung · Exynos 850 firmwareEPSS 0.09%via NVD
CVE-2026-23793Low· 3.5
1w ago

An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400

An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.

SunlitSamsung · Exynos 1330 firmwareEPSS 0.20%via NVD
CVE-2026-23788Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.

SunlitSamsung · Exynos 1280 firmwareEPSS 0.10%via NVD
CVE-2026-21090High· 7.8⚖ disputed
1w ago

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21091High· 7.8⚖ disputed
1w ago

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21102Medium· 6.7⚖ disputed
1w ago

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2026-21095Critical· 9.8
1w ago

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Midnightsamsung · androidEPSS 0.46%via NVD
CVE-2026-21089High· 7.8
1w ago

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21096Critical· 9.8
1w ago

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Midnightsamsung · androidEPSS 0.46%via NVD
CVE-2026-21094High· 8.8⚖ disputed
1w ago

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

Twilightsamsung · androidEPSS 0.16%via NVD
CVE-2026-21088High· 7.8
1w ago

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Twilightsamsung · androidEPSS 0.11%via NVD
CVE-2026-21104Medium· 6.7
1w ago

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Sunlitsamsung · androidEPSS 0.10%via NVD
CVE-2026-21085Medium· 6.7
1w ago

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Sunlitsamsung · androidEPSS 0.11%via NVD
samsung vulnerabilities (CVEs) · VulnSea