Samsung
Samsung Android: vulnerabilidades y CVE
Samsung Android tiene 502 vulnerabilidades publicadas, 102 de ellas en los últimos 12 meses. 12 son críticas y 12 figuran en el catálogo de explotación activa de CISA.
CVE502
Últimos 12 meses102
Críticas12
Explotadas activamente12
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21042 | Crítica (9.8) | 33% | ⚠ Explotación activa | 12 sept 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. |
| CVE-2025-21043 | Crítica (9.8) | 2.1% | ⚠ Explotación activa | 12 sept 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. |
| CVE-2021-25487 | Alta (7.8) | 0.64% | ⚠ Explotación activa | 6 oct 2021 | Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer. |
| CVE-2021-25489 | Media (5.5) | 0.53% | ⚠ Explotación activa | 6 oct 2021 | Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. |
| CVE-2021-25372 | Media (6.7) | 0.80% | ⚠ Explotación activa | 26 mar 2021 | An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
| CVE-2021-25371 | Media (6.7) | 0.80% | ⚠ Explotación activa | 26 mar 2021 | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
| CVE-2021-25394 | Media (6.4) | 0.40% | ⚠ Explotación activa | 11 jun 2021 | A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised. |
| CVE-2021-25395 | Media (6.4) | 0.37% | ⚠ Explotación activa | 11 jun 2021 | A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. |
| CVE-2023-21492 | Media (4.4) | 2.6% | ⚠ Explotación activa | 4 may 2023 | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. |
| CVE-2021-25337 | Alta (7.1) | 2.8% | ⚠ Explotación activa | 4 mar 2021 | Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. |
| CVE-2021-25369 | Media (5.5) | 1.1% | ⚠ Explotación activa | 26 mar 2021 | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. |
| CVE-2021-25370 | Media (4.4) | 0.89% | ⚠ Explotación activa | 26 mar 2021 | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21112 | Media (5.1) | 0.09% | — | 9 sept 2026 | Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability. |
| CVE-2026-21104 | Alta (7.1) | 0.10% | — | 9 sept 2026 | Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code. |
| CVE-2026-21103 | Media (6.8) | 0.18% | — | 9 sept 2026 | Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege. |
| CVE-2026-21102 | Crítica (9.3) | 0.12% | — | 9 sept 2026 | Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege. |
| CVE-2026-21101 | Alta (8.4) | 0.12% | — | 9 sept 2026 | Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege. |
| CVE-2026-21100 | Media (6.9) | 0.09% | — | 9 sept 2026 | Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity. |
| CVE-2026-21099 | Media (5.1) | 0.09% | — | 9 sept 2026 | Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information. |
| CVE-2026-21098 | Media (6.9) | 0.09% | — | 9 sept 2026 | Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction. |
| CVE-2026-21097 | Media (4.6) | 0.12% | — | 9 sept 2026 | Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity. |
| CVE-2026-21096 | Crítica (9.2) | 0.46% | — | 9 sept 2026 | Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. |
| CVE-2026-21095 | Crítica (9.2) | 0.46% | — | 9 sept 2026 | Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. |
| CVE-2026-21094 | Media (6.1) | 0.16% | — | 9 sept 2026 | Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory. |
| CVE-2026-21093 | Media (5.6) | 0.09% | — | 9 sept 2026 | Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. |
| CVE-2026-21092 | Alta (8.8) | 0.32% | — | 9 sept 2026 | Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege. |
| CVE-2026-21091 | Media (4.8) | 0.10% | — | 9 sept 2026 | Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21090 | Media (4.8) | 0.10% | — | 9 sept 2026 | Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21089 | Media (6.9) | 0.10% | — | 9 sept 2026 | Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21088 | Media (6.9) | 0.11% | — | 9 sept 2026 | Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21087 | Alta (8.6) | 0.12% | — | 9 sept 2026 | Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege. |
| CVE-2026-21086 | Media (4.8) | 0.11% | — | 9 sept 2026 | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. |
| CVE-2026-21085 | Alta (8.4) | 0.11% | — | 9 sept 2026 | Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. |
| CVE-2026-21073 | Media (5.2) | 0.21% | — | 10 ago 2026 | Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. |
| CVE-2026-21072 | Media (5.1) | 0.15% | — | 10 ago 2026 | Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21071 | Media (5.1) | 0.15% | — | 10 ago 2026 | Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21070 | Media (5.1) | 0.21% | — | 10 ago 2026 | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. |
| CVE-2026-21069 | Media (5.1) | 0.15% | — | 10 ago 2026 | Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21068 | Alta (8.4) | 0.17% | — | 10 ago 2026 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. |
| CVE-2026-21067 | Media (5.1) | 0.15% | — | 10 ago 2026 | Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21066 | Media (5.1) | 0.15% | — | 10 ago 2026 | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
| CVE-2026-21065 | Media (4.8) | 0.15% | — | 10 ago 2026 | Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Samsung
Exynos 1380 Firmware · 125Exynos 1280 Firmware · 118Exynos 980 Firmware · 114Exynos 1330 Firmware · 99Exynos 850 Firmware · 97Exynos 1080 Firmware · 97Exynos 1480 Firmware · 90Exynos 2200 Firmware · 88Exynos W920 Firmware · 75Exynos 2400 Firmware · 72Exynos 2100 Firmware · 65Exynos W930 Firmware · 65