CVE Tools

Samsung Mobile Devices

852 CVEs tracked. 13 of them are in CISA KEV.

This hub aggregates every CVE we track for Samsung Mobile Devices, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Samsung Mobile Devices CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Samsung Mobile Devices CVEs per month
MonthCVEs
2024-108
2024-1114
2024-127
2025-010
2025-0217
2025-036
2025-0415
2025-0513
2025-0610
2025-0710
2025-088
2025-0928
2025-1012
2025-114
2025-128
2026-017
2026-027
2026-035
2026-049
2026-057
2026-068
2026-0714
2026-0816
2026-0920

Severity

How the 852 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical91%
  • High15619%
  • Medium58570%
  • Low8510%

Latest CVEs

The 15 most recently published vulnerabilities affecting Samsung Mobile Devices.

  1. CVE-2026-21104Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.6.7
  2. CVE-2026-21103Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.6.1
  3. CVE-2026-21102Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.6.7
  4. CVE-2026-21101Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.6.7
  5. CVE-2026-21100Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.7.1
  6. CVE-2026-21099Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.5.5
  7. CVE-2026-21098Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.—
  8. CVE-2026-21097Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.6.7
  9. CVE-2026-21096Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.9.8
  10. CVE-2026-21095Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.9.8
  11. CVE-2026-21094Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.8.8
  12. CVE-2026-21093Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.6.7
  13. CVE-2026-21092Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.5.3
  14. CVE-2026-21091Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
  15. CVE-2026-21090Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store