Samsung
695 known vulnerabilities
Top Products
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows ad
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write o
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensiti
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local att
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execut
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds me
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write ou
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bo
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers t
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard d
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM relate
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with
In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l
Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to ac
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an
Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive informa
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive infor
Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 i
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.1
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. U
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileg
Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive in
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers
Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attack
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive i
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Es
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Man
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Man
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:
Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot:
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This is
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Wa
Frequently Asked Questions
How many CVEs affect Samsung?
Samsung has 695 CVE records in our database, including 124 critical and 245 high severity vulnerabilities.
What are the most severe Samsung vulnerabilities?
Samsung has 124 critical severity (CVSS 9.0+) and 245 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Samsung vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Samsung products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Samsung Vulnerabilities
CyberStrike scans your infrastructure for Samsung vulnerabilities and provides real-time remediation guidance.
Get Started