VulnSea

samsung has 56 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 43 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 40. The median CVSS is 5.5 (medium), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-787 (13) and CWE-122 (4). Most affected products: android (23), Exynos 1330 firmware (7), Exynos 1280 firmware (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
—
Last 90 days
43 prev 1

Products

  • android 23
  • Exynos 1330 firmware 7
  • Exynos 1280 firmware 5
  • Exynos 850 firmware 4
  • rlottie 3
  • Exynos 1580 firmware 2
56
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

samsung vulnerabilities

CVEs affecting samsung, newest first. Open any entry for full detail, references, and exploit status.

56 CVEsRSS

CVE-2026-21104Medium· 6.7
2w ago

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

▾ Sunlitsamsung · androidEPSS 0.10%via NVD
CVE-2026-21085Medium· 6.7
2w ago

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.11%via NVD
CVE-2026-21108Medium· 5.5
2w ago

Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

▾ Sunlitsamsung · bixbyEPSS 0.09%via NVD
CVE-2026-21107Medium· 5.5
2w ago

Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.

▾ Sunlitsamsung · notesEPSS 0.09%via NVD
CVE-2026-21105Medium· 5.5
2w ago

Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.

Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.

▾ Sunlitsamsung · collectionEPSS 0.09%via NVD
CVE-2026-21103Medium· 6.1
2w ago

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

▾ Sunlitsamsung · androidEPSS 0.18%via NVD
CVE-2026-21099Medium· 5.5
2w ago

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

▾ Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-21097Medium· 6.7⚖ disputed
2w ago

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

▾ Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2026-21093Medium· 6.7
2w ago

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-21092Medium· 5.3⚖ disputed
2w ago

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

▾ Sunlitsamsung · androidEPSS 0.32%via NVD
CVE-2026-19518Medium· 6.5
1mo ago

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

▾ Sunlitsamsung · rlottieEPSS 0.36%via NVD
CVE-2026-19517Medium· 6.5
1mo ago

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

▾ Sunlitsamsung · rlottieEPSS 0.36%via NVD
CVE-2026-18772Medium· 6.5
1mo ago

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

▾ Sunlitsamsung · rlottieEPSS 0.36%via NVD
CVE-2026-6840Medium· 5.5
5mo ago

Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.

Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.

▾ Sunlitsamsung · oneEPSS 0.15%via NVD
CVE-2025-62817High· 7.5
6mo ago

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.

▾ Twilightsamsung · exynos_1280_firmwareEPSS 0.29%via NVD
CVE-2025-58488Medium· 4.5
9mo ago

Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information

Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information. User interaction is required for triggering this vulnerability.

▾ Sunlitsamsung · smart_touch_callEPSS 0.43%via NVD
CVE-2025-58486Medium· 4.0
9mo ago

Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

▾ Sunlitsamsung · accountEPSS 0.19%via NVD
CVE-2025-58485Medium· 5.5
9mo ago

Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.

Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.

▾ Sunlitsamsung · internetEPSS 0.12%via NVD
CVE-2025-58483Medium· 5.9
9mo ago

Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.

Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.

▾ Sunlitsamsung · galaxy_storeEPSS 0.10%via NVD
CVE-2025-58479Medium· 4.3
9mo ago

Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.27%via NVD
CVE-2025-58478Medium· 4.3
9mo ago

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.26%via NVD
CVE-2025-58477Medium· 4.3
9mo ago

Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.26%via NVD
CVE-2025-58476Medium· 4.2
9mo ago

Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.15%via NVD
CVE-2025-58475Medium· 5.6
9mo ago

Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2025-21080Medium· 6.2
9mo ago

Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

▾ Sunlitsamsung · androidEPSS 0.10%via NVD
CVE-2025-21072Medium· 5.7
9mo ago

Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.11%via NVD
samsung vulnerabilities (CVEs) — page 2 · VulnSea